VendorsFormtoolsform_tools3.1.1
Vulnerabilities

Formtools Form Tools 3.1.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2024-22718
Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the application URL.
Published 2024-04-11 · Analyzed
9.6EPSS 0.007
CVE-2024-22719
SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when searching for a client.
Published 2024-04-11 · Analyzed
8.1EPSS 0.005
CVE-2024-22722
Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.
Published 2024-04-11 · Analyzed
7.2EPSS 0.009
CVE-2024-22721
Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link.
Published 2024-04-11 · Analyzed
6.3EPSS 0.002
CVE-2024-22637
Form Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /form_builder/preview.php?form_id=2.
Published 2024-01-25 · Modified
6.1EPSS 0.005
CVE-2024-22717
Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the First Name field in the application.
Published 2024-04-11 · Analyzed
6.1EPSS 0.004
CVE-2024-6936
formtools.org Form Tools Setting code injection
Published 2024-07-21 · Modified
5.1EPSS 0.004
CVE-2024-6934
formtools.org Form Tools cross site scripting
Published 2024-07-21 · Modified
5.1EPSS 0.004
CVE-2024-6937
formtools.org Form Tools Import Option List edit.php curl_exec file inclusion
Published 2024-07-21 · Modified
5.1EPSS 0.004
CVE-2024-6935
formtools.org Form Tools User Settings Page cross site scripting
Published 2024-07-21 · Modified
5.1EPSS 0.003