Vulnerabilities > Tripetto > Tripetto > 5.3.2

DATE CVE VULNERABILITY TITLE RISK
2025-03-15 CVE-2025-1530 Cross-Site Request Forgery (CSRF) vulnerability in Tripetto
The Tripetto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.9.
network
low complexity
tripetto CWE-352
4.3
2025-03-15 CVE-2024-13497 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tripetto
The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via attachment uploads in all versions up to, and including, 8.0.9 due to insufficient input sanitization and output escaping.
network
low complexity
tripetto CWE-80
6.1
2024-11-15 CVE-2024-10260 Unspecified vulnerability in Tripetto
The Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, and including, 8.0.3 due to insufficient input sanitization and output escaping.
network
low complexity
tripetto
6.1