Vulnerabilities > Cimatti

DATE CVE VULNERABILITY TITLE RISK
2023-11-13 CVE-2023-47230 Cross-Site Request Forgery (CSRF) vulnerability in Cimatti Wordpress Contact Forms
Cross-Site Request Forgery (CSRF) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.6.0 versions.
network
low complexity
cimatti CWE-352
8.8
2023-06-13 CVE-2023-2563 Unspecified vulnerability in Cimatti Contact Forms
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7.
network
low complexity
cimatti
4.3
2023-04-07 CVE-2023-28781 Cross-site Scripting vulnerability in Cimatti Wordpress Contact Forms
Unauth.
network
low complexity
cimatti CWE-79
6.1
2023-04-07 CVE-2023-28789 Cross-site Scripting vulnerability in Cimatti Wordpress Contact Forms
Unauth.
network
low complexity
cimatti CWE-79
6.1
2021-10-25 CVE-2021-24744 Cross-site Scripting vulnerability in Cimatti Contact Forms
The WordPress Contact Forms by Cimatti WordPress plugin before 1.4.12 does not sanitise and escape the Form Title before outputting it in some admin pages.
network
cimatti CWE-79
3.5