CVE-2024-37463
- EPSS 0.34%
- Veröffentlicht 01.11.2024 15:15:26
- Zuletzt bearbeitet 07.02.2025 15:12:30
Missing Authorization vulnerability in CRM Perks CRM Perks Forms allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CRM Perks Forms: from n/a through 1.1.5.
CVE-2024-7484
- EPSS 11.98%
- Veröffentlicht 06.08.2024 02:15:35
- Zuletzt bearbeitet 07.02.2025 19:12:46
The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'handle_uploaded_files' function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers w...
CVE-2024-30446
- EPSS 0.16%
- Veröffentlicht 29.03.2024 17:15:13
- Zuletzt bearbeitet 07.02.2025 16:56:52
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms allows Stored XSS.This issue affects CRM Perks Forms: from n/a through 1.1.4.
- EPSS 0.3%
- Veröffentlicht 29.03.2024 14:15:13
- Zuletzt bearbeitet 07.02.2025 16:56:00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4.
CVE-2024-30499
- EPSS 0.39%
- Veröffentlicht 29.03.2024 14:15:13
- Zuletzt bearbeitet 07.02.2025 16:56:36
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4.
CVE-2023-51536
- EPSS 0.06%
- Veröffentlicht 01.02.2024 11:15:09
- Zuletzt bearbeitet 21.11.2024 08:38:19
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms – WordPress Form Builder allows Stored XSS.This issue affects CRM Perks Forms – WordPress Form Builder: from n/a through 1...
CVE-2023-2836
- EPSS 0.15%
- Veröffentlicht 31.05.2023 04:15:10
- Zuletzt bearbeitet 21.11.2024 07:59:23
The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...
CVE-2022-38467
- EPSS 17.68%
- Veröffentlicht 14.01.2023 11:15:09
- Zuletzt bearbeitet 21.11.2024 07:16:32
Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.