Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown
CVE-2024-56003
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in David Cramer Caldera SMTP Mailer.This issue affects Caldera SMTP Mailer: from n/a through 1.0.1.
0
Attacker Value
Unknown
CVE-2024-52347
Disclosure Date: November 18, 2024 (last updated November 19, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP website creator Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera allows Stored XSS.This issue affects Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera: from n/a through 4.0.
0
Attacker Value
Unknown
CVE-2023-2330
Disclosure Date: July 17, 2023 (last updated October 08, 2023)
The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-40606
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40605.
0
Attacker Value
Unknown
CVE-2022-41139
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on agents.
0
Attacker Value
Unknown
CVE-2022-40605
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40606.
0
Attacker Value
Unknown
CVE-2022-0879
Disclosure Date: April 18, 2022 (last updated February 23, 2025)
The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2021-36914
Disclosure Date: April 12, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability leading to Reflected Cross-Site Scripting (XSS) in CalderaWP License Manager (WordPress plugin) <= 1.2.11.
0
Attacker Value
Unknown
CVE-2021-42559
Disclosure Date: January 12, 2022 (last updated February 23, 2025)
An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is restarted.
0
Attacker Value
Unknown
CVE-2021-42558
Disclosure Date: January 12, 2022 (last updated February 23, 2025)
An issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated and unauthenticated attackers.
0