Skip to main content

Vendor/product archive

strategy11 / formidable_forms CVEs

Beta · best-effort

8 CVEs tagged to strategy11 / formidable_forms0 Critical, 2 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2022-45806

Published Dec 13, 2024

Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects For…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11188

Published Nov 23, 2024

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scri…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9768

Published Nov 21, 2024

The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cros…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6725

Published Jul 31, 2024

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23522

Published May 17, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affec…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0660

Published Feb 5, 2024

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-1405

Published Jan 16, 2024

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2877

Published Jun 27, 2023

The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a use…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1