Show filters
28 Total Results
Displaying 1-10 of 28
Sort by:
Attacker Value
Unknown
CVE-2019-25012
Disclosure Date: January 01, 2021 (last updated February 22, 2025)
The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml page. NOTE: This project is not covered by Drupal's security advisory policy.
0
Attacker Value
Unknown
CVE-2020-12635
Disclosure Date: June 29, 2020 (last updated February 21, 2025)
XSS exists in the WebForms Pro M2 extension before 2.9.17 for Magento 2 via the textarea field.
0
Attacker Value
Unknown
CVE-2019-18924
Disclosure Date: November 12, 2019 (last updated November 27, 2024)
Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with ../ (and variations), it is possible to list all the directories and check if a particular file exists.
0
Attacker Value
Unknown
CVE-2019-18925
Disclosure Date: November 12, 2019 (last updated November 27, 2024)
Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication.
0
Attacker Value
Unknown
CVE-2015-5494
Disclosure Date: August 18, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Webform Matrix Component module 7.x-4.x before 7.x-4.13 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-4374
Disclosure Date: June 16, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.23, 7.x-3.x before 7.x-3.23, and 7.x-4.x before 7.x-4.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a component name in the recipient (To) address of an email.
0
Attacker Value
Unknown
CVE-2015-4354
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Ubercart Webform Integration module before 6.x-1.8 and 7.x before 7.x-2.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-4384
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Ubercart Webform Checkout Pane module 6.x-3.x before 6.x-3.10 and 7.x-3.x before 7.x-3.11 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-4356
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the view-based webform results table in the Webform module 7.x-4.x before 7.x-4.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a webform.
0
Attacker Value
Unknown
CVE-2015-4357
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.22, 7.x-3.x before 7.x-3.22, and 7.x-4.x before 7.x-4.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title, which is used as the default title of a webform block.
0