VendorscformsII Projectcformsiiany version
Vulnerabilities

cformsII Project cformsII any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2015-9333
The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
Published 2019-08-22 · Modified
9.8EPSS 0.018
CVE-2017-18570
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.
Published 2019-08-22 · Modified
9.8EPSS 0.018
CVE-2019-15238
The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.
Published 2019-08-20 · Modified
8.8EPSS 0.007
CVE-2023-25449
WordPress CformsII Plugin <=15.0.4 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-06-15 · Modified
8.8EPSS 0.003
CVE-2014-10392
The cforms2 plugin before 10.2 for WordPress has XSS.
Published 2019-08-22 · Modified
6.1EPSS 0.009
CVE-2014-10377
The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.
Published 2019-08-21 · Modified
6.1EPSS 0.009
CVE-2017-18559
The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.
Published 2019-08-21 · Modified
6.1EPSS 0.009
CVE-2014-10393
The cforms2 plugin before 10.5 for WordPress has XSS.
Published 2019-08-22 · Modified
6.1EPSS 0.009
CVE-2023-52203
WordPress CformsII Plugin <= 15.0.5 is vulnerable to Cross Site Scripting (XSS)
Published 2024-01-08 · Modified
5.9EPSS 0.003