Vulnerabilities > Bestwebsoft > Contact Form TO DB > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-10-31 CVE-2023-36508 SQL Injection vulnerability in Bestwebsoft Contact Form to DB
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress contact-form-to-db allows SQL Injection.This issue affects Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress: from n/a through 1.7.1.
network
low complexity
bestwebsoft CWE-89
critical
9.8