Vulnerabilities > Ciphercoin > Contact Form 7 Database Addon > High

DATE CVE VULNERABILITY TITLE RISK
2021-12-22 CVE-2021-36886 Cross-Site Request Forgery (CSRF) vulnerability in Ciphercoin Contact Form 7 Database Addon
Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.5.9).
network
low complexity
ciphercoin CWE-352
8.8
2021-03-18 CVE-2021-24144 Improper Neutralization of Formula Elements in a CSV File vulnerability in Ciphercoin Contact Form 7 Database Addon
Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.
local
low complexity
ciphercoin CWE-1236
7.8