CVE-2025-0817
- EPSS 0.57%
- Veröffentlicht 18.02.2025 11:15:12
- Zuletzt bearbeitet 21.02.2025 12:15:11
The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.9.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a...
CVE-2024-13783
- EPSS 0.11%
- Veröffentlicht 18.02.2025 11:15:11
- Zuletzt bearbeitet 21.02.2025 12:19:42
The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in formcraft-main.php in all versions up to, and including, 3.9.11. This makes it possible for authenticated attackers, with Subscriber-...
CVE-2023-47823
- EPSS 0.21%
- Veröffentlicht 09.12.2024 13:15:31
- Zuletzt bearbeitet 09.12.2024 13:15:31
Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2.7.
CVE-2024-43157
- EPSS 0.25%
- Veröffentlicht 01.11.2024 15:15:40
- Zuletzt bearbeitet 01.11.2024 20:24:53
Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2.10.
CVE-2023-2592
- EPSS 0.25%
- Veröffentlicht 27.06.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:58:53
The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
CVE-2023-22717
- EPSS 0.1%
- Veröffentlicht 15.05.2023 12:15:09
- Zuletzt bearbeitet 21.11.2024 07:45:17
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in nCrafts FormCraft plugin <= 1.2.6 versions.
CVE-2022-1647
- EPSS 0.21%
- Veröffentlicht 08.06.2022 10:15:10
- Zuletzt bearbeitet 21.11.2024 06:41:10
The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2017-18600
- EPSS 0.18%
- Veröffentlicht 10.09.2019 12:15:10
- Zuletzt bearbeitet 21.11.2024 03:20:29
The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.
CVE-2019-15114
- EPSS 0.09%
- Veröffentlicht 16.08.2019 21:15:13
- Zuletzt bearbeitet 21.11.2024 04:28:04
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
CVE-2019-5920
- EPSS 0.17%
- Veröffentlicht 12.03.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:45:44
Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.