Vulnerabilities > Fluentforms

DATE CVE VULNERABILITY TITLE RISK
2024-12-14 CVE-2024-10646 Cross-site Scripting vulnerability in Fluentforms Contact Form
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping.
network
low complexity
fluentforms CWE-79
6.1
2024-10-05 CVE-2024-9528 Cross-site Scripting vulnerability in Fluentforms Contact Form
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form label fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping.
network
low complexity
fluentforms CWE-79
4.8
2024-09-01 CVE-2024-5053 Missing Authorization vulnerability in Fluentforms Contact Form
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function in all versions up to, and including, 5.1.18.
network
low complexity
fluentforms CWE-862
4.3
2024-07-27 CVE-2024-6703 Cross-site Scripting vulnerability in Fluentforms Contact Form
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ and 'btn_txt' parameters in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping.
network
low complexity
fluentforms CWE-79
5.4
2024-07-27 CVE-2024-6518 Cross-site Scripting vulnerability in Fluentforms Contact Form
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping.
network
low complexity
fluentforms CWE-79
4.8
2024-07-27 CVE-2024-6520 Cross-site Scripting vulnerability in Fluentforms Contact Form
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping.
network
low complexity
fluentforms CWE-79
4.8
2024-07-27 CVE-2024-6521 Cross-site Scripting vulnerability in Fluentforms Contact Form
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping.
network
low complexity
fluentforms CWE-79
4.8
2024-05-22 CVE-2024-4157 Deserialization of Untrusted Data vulnerability in Fluentforms Contact Form
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted input in the extractDynamicValues function.
network
low complexity
fluentforms CWE-502
8.8
2024-05-18 CVE-2024-2772 Cross-site Scripting vulnerability in Fluentforms Contact Form
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in all versions up to, and including, 5.1.13 due to insufficient input sanitization and output escaping.
network
low complexity
fluentforms CWE-79
5.4
2024-05-18 CVE-2024-4709 Cross-site Scripting vulnerability in Fluentforms Contact Form
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subject’ parameter in versions up to, and including, 5.1.16 due to insufficient input sanitization and output escaping.
network
low complexity
fluentforms CWE-79
5.4