Vulnerabilities > Strategy11 > Formidable Forms > 6.2.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-07-31 | CVE-2024-6725 | Cross-site Scripting vulnerability in Strategy11 Formidable Forms The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ parameter in all versions up to, and including, 6.11.1 due to insufficient input sanitization and output escaping. | 5.4 |
2024-05-17 | CVE-2024-23522 | Cross-site Scripting vulnerability in Strategy11 Formidable Forms Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affects Formidable Forms: from n/a through 6.7. | 6.1 |
2024-02-05 | CVE-2024-0660 | Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Formidable Forms The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.2. | 4.3 |
2023-06-27 | CVE-2023-2877 | Unspecified vulnerability in Strategy11 Formidable Forms The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. | 8.8 |