Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown

CVE-2024-56003

Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in David Cramer Caldera SMTP Mailer.This issue affects Caldera SMTP Mailer: from n/a through 1.0.1.
0
Attacker Value
Unknown

CVE-2024-52347

Disclosure Date: November 18, 2024 (last updated November 19, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP website creator Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera allows Stored XSS.This issue affects Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera: from n/a through 4.0.
0
Attacker Value
Unknown

CVE-2023-2330

Disclosure Date: July 17, 2023 (last updated October 08, 2023)
The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Attacker Value
Unknown

CVE-2022-40606

Disclosure Date: October 17, 2022 (last updated October 08, 2023)
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40605.
Attacker Value
Unknown

CVE-2022-41139

Disclosure Date: October 17, 2022 (last updated October 08, 2023)
MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on agents.
Attacker Value
Unknown

CVE-2022-40605

Disclosure Date: October 17, 2022 (last updated October 08, 2023)
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40606.
Attacker Value
Unknown

CVE-2022-0879

Disclosure Date: April 18, 2022 (last updated February 23, 2025)
The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2021-36914

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability leading to Reflected Cross-Site Scripting (XSS) in CalderaWP License Manager (WordPress plugin) <= 1.2.11.
Attacker Value
Unknown

CVE-2021-42559

Disclosure Date: January 12, 2022 (last updated February 23, 2025)
An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is restarted.
Attacker Value
Unknown

CVE-2021-42558

Disclosure Date: January 12, 2022 (last updated February 23, 2025)
An issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated and unauthenticated attackers.