CVE-2025-1530
- EPSS 0.07%
- Veröffentlicht 15.03.2025 12:15:11
- Zuletzt bearbeitet 25.03.2025 20:02:28
The Tripetto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.9. This is due to missing nonce validation. This makes it possible for unauthenticated attackers to delete arbitrary results via a...
CVE-2024-13497
- EPSS 0.68%
- Veröffentlicht 15.03.2025 04:22:08
- Zuletzt bearbeitet 28.03.2025 15:22:59
The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via attachment uploads in all versions up to, and including, 8.0.9 due to insufficient input sanitiz...
CVE-2025-22295
- EPSS 0.1%
- Veröffentlicht 09.01.2025 16:16:25
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tripetto WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto tripetto allows Stored XSS.This issue affects WordPress for...
CVE-2024-10260
- EPSS 0.77%
- Veröffentlicht 15.11.2024 06:15:03
- Zuletzt bearbeitet 08.04.2026 18:19:05
The Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, and including, 8.0.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attack...
CVE-2021-36895
- EPSS 0.31%
- Veröffentlicht 26.04.2022 19:15:49
- Zuletzt bearbeitet 21.11.2024 06:14:16
Unauthenticated Cross-Site Scripting (XSS) vulnerability in Tripetto's Tripetto plugin <= 5.1.4 on WordPress via SVG image upload.