Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
7.2
CVE-2026-18409
- EPSS -
- Veröffentlicht 21.08.2026 04:18:01
- Zuletzt bearbeitet 21.08.2026 04:18:01
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all versions up to, and including, 2.0.0.2 due to insufficient input sanitization and output escaping. This make...
8.1
CVE-2026-10818
- EPSS 0.42%
- Veröffentlicht 25.07.2026 07:17:08
- Zuletzt bearbeitet 27.07.2026 20:25:13
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file co...
9.8
CVE-2022-3574
- EPSS 1.32%
- Veröffentlicht 14.11.2022 15:15:52
- Zuletzt bearbeitet 30.04.2025 16:15:23
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
1