Vulnerabilities > Codepeople > Calculated Fields Form > 1.2.2

DATE CVE VULNERABILITY TITLE RISK
2024-03-27 CVE-2024-29759 Unspecified vulnerability in Codepeople Calculated Fields Form
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Calculated Fields Form allows Reflected XSS.This issue affects Calculated Fields Form: from n/a through 1.2.54.
network
low complexity
codepeople
6.1
2024-02-02 CVE-2024-0963 Cross-site Scripting vulnerability in Codepeople Calculated Fields Form
The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's CP_CALCULATED_FIELDS shortcode in all versions up to, and including, 1.2.52 due to insufficient input sanitization and output escaping on user supplied 'location' attribute.
network
low complexity
codepeople CWE-79
5.4
2023-12-29 CVE-2023-51517 Unspecified vulnerability in Codepeople Calculated Fields Form
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: from n/a through 1.2.28.
network
low complexity
codepeople
5.4