Filtered by vendor Wpforms
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-3574 | 1 Wpforms | 1 Wpforms Pro | 2022-11-16 | N/A | 9.8 CRITICAL |
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection. | |||||
CVE-2020-10385 | 1 Wpforms | 1 Contact Form | 2022-10-06 | 3.5 LOW | 5.4 MEDIUM |
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress. |