Vulnerabilities > Themekraft

DATE CVE VULNERABILITY TITLE RISK
2023-03-16 CVE-2022-38971 Unspecified vulnerability in Themekraft Post Form Registration Form Profile Form for User Profiles and Content Forms
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.
network
low complexity
themekraft
5.4
2023-02-23 CVE-2023-26326 Deserialization of Untrusted Data vulnerability in Themekraft Buddyforms
The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue.
network
low complexity
themekraft CWE-502
critical
9.8
2019-08-27 CVE-2018-21003 SQL Injection vulnerability in Themekraft Buddyforms
The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
network
low complexity
themekraft CWE-89
critical
9.8