Skip to main content

Vendor/product archive

strategy11 / formidable_form_builder CVEs

Beta · best-effort

9 CVEs tagged to strategy11 / formidable_form_builder2 Critical, 2 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2017-20194

Published Oct 16, 2024

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This mak…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-20192

Published Oct 16, 2024

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions b…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6842

Published Jan 9, 2024

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name fi…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-6830

Published Jan 9, 2024

The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrar…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-0816

Published Mar 27, 2023

The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-24884

Published Oct 25, 2021

The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remo…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-24608

Published Oct 25, 2021

The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1