Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Wpeverest Subscribe
Filtered by product Everest Forms
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-13575 1 Wpeverest 1 Everest Forms 2023-02-27 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php
CVE-2021-24907 1 Wpeverest 1 Everest Forms 2021-12-27 4.3 MEDIUM 6.1 MEDIUM
The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue