Show filters
663 Total Results
Displaying 151-160 of 663
Sort by:
Attacker Value
Unknown
CVE-2024-5325
Disclosure Date: July 12, 2024 (last updated July 13, 2024)
The Form Vibes plugin for WordPress is vulnerable to SQL Injection via the ‘fv_export_data’ parameter in all versions up to, and including, 1.4.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown
CVE-2024-6550
Disclosure Date: July 10, 2024 (last updated January 05, 2025)
The Gravity Forms: Multiple Form Instances plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.1. This is due to the plugin leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
0
Attacker Value
Unknown
CVE-2024-37934
Disclosure Date: July 09, 2024 (last updated August 30, 2024)
Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4.
0
Attacker Value
Unknown
CVE-2024-6069
Disclosure Date: July 09, 2024 (last updated January 05, 2025)
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation/deactivation due to missing capability checks on the pieregister_install_addon, pieregister_activate_addon and pieregister_deactivate_addon functions in all versions up to, and including, 3.8.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install, activate and deactivate arbitrary plugins. As a result attackers might achieve code execution on the targeted server
0
Attacker Value
Unknown
CVE-2024-6313
Disclosure Date: July 09, 2024 (last updated January 05, 2025)
The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' function in versions up to, and including, 2.2.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2022-45803
Disclosure Date: June 21, 2024 (last updated June 25, 2024)
Missing Authorization vulnerability in Nikolay Strikhar WordPress Form Builder Plugin – Gutenberg Forms.This issue affects WordPress Form Builder Plugin – Gutenberg Forms: from n/a through 2.2.8.3.
0
Attacker Value
Unknown
CVE-2023-38393
Disclosure Date: June 19, 2024 (last updated August 01, 2024)
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
0
Attacker Value
Unknown
CVE-2023-38386
Disclosure Date: June 19, 2024 (last updated June 20, 2024)
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
0
Attacker Value
Unknown
CVE-2023-51377
Disclosure Date: June 14, 2024 (last updated August 08, 2024)
Missing Authorization vulnerability in WPEverest Everest Forms.This issue affects Everest Forms: from n/a through 2.0.3.
0
Attacker Value
Unknown
CVE-2023-51524
Disclosure Date: June 12, 2024 (last updated July 20, 2024)
Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.18.
0