Skip to main content

Vendor archive

strategy11 CVEs

Beta · best-effort

29 CVEs tagged to vendor strategy113 Critical, 8 High, 18 Medium, 0 Low, 0 Unrated.

CVE-2022-45806

Published Dec 13, 2024

Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects For…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11188

Published Nov 23, 2024

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scri…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9768

Published Nov 21, 2024

The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cros…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-20194

Published Oct 16, 2024

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This mak…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-20192

Published Oct 16, 2024

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions b…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6725

Published Jul 31, 2024

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31350

Published Jun 9, 2024

Missing Authorization vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23522

Published May 17, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affec…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1290

Published Mar 11, 2024

The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from rendering sensitive shortcodes, allowing them to generate, and le…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0660

Published Feb 5, 2024

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-1405

Published Jan 16, 2024

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-6842

Published Jan 9, 2024

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name fi…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-6830

Published Jan 9, 2024

The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrar…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-41801

Published Oct 6, 2023

Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2877

Published Jun 27, 2023

The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a use…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0816

Published Mar 27, 2023

The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-3254

Published Oct 31, 2022

The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action availabl…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-24884

Published Oct 25, 2021

The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remo…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-24608

Published Oct 25, 2021

The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 29 CVEsPage 1 of 2