Vulnerabilities > Basixonline > NEX Forms > 8.3.3

DATE CVE VULNERABILITY TITLE RISK
2023-07-17 CVE-2023-0439 Unspecified vulnerability in Basixonline Nex-Forms
The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues.
network
low complexity
basixonline
5.4
2023-05-08 CVE-2023-2114 Unspecified vulnerability in Basixonline Nex-Forms
The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query.
network
low complexity
basixonline
7.2