Show filters
663 Total Results
Displaying 171-180 of 663
Sort by:
Attacker Value
Unknown

CVE-2024-5324

Disclosure Date: June 06, 2024 (last updated February 26, 2025)
The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in versions 2.7.1 to 2.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.
Attacker Value
Unknown

CVE-2024-2368

Disclosure Date: June 05, 2024 (last updated February 26, 2025)
The Mollie Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.13. This is due to missing or incorrect nonce validation on the duplicateForm() function. This makes it possible for unauthenticated attackers to duplicate forms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-5149

Disclosure Date: June 05, 2024 (last updated February 26, 2025)
The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification.
Attacker Value
Unknown

CVE-2024-25095

Disclosure Date: June 04, 2024 (last updated February 26, 2025)
Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affects Easy Forms for Mailchimp: from n/a through 6.9.0.
Attacker Value
Unknown

CVE-2023-48276

Disclosure Date: June 04, 2024 (last updated February 26, 2025)
Improper Restriction of Excessive Authentication Attempts vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Functionality Bypass.This issue affects WP Forms Puzzle Captcha: from n/a through 4.1.
0
Attacker Value
Unknown

CVE-2024-35239

Disclosure Date: May 28, 2024 (last updated February 26, 2025)
Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to one of the patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).
0
Attacker Value
Unknown

CVE-2024-35174

Disclosure Date: May 17, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Flothemes Flo Forms.This issue affects Flo Forms: from n/a through 1.0.42.
0
Attacker Value
Unknown

CVE-2024-32830

Disclosure Date: May 17, 2024 (last updated February 26, 2025)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forgery, Relative Path Traversal.This issue affects BuddyForms: from n/a through 2.8.8.
0
Attacker Value
Unknown

CVE-2024-32512

Disclosure Date: May 17, 2024 (last updated February 26, 2025)
Client-Side Enforcement of Server-Side Security vulnerability in weForms allows Removing Important Client Functionality.This issue affects weForms: from n/a through 1.6.20.
0
Attacker Value
Unknown

CVE-2024-23522

Disclosure Date: May 17, 2024 (last updated February 26, 2025)
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affects Formidable Forms: from n/a through 6.7.