← Back

Caldera Forms

caldera_forms

Vendor: Calderaforms • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Calderaforms
1Caldera Forms
Jun 17, 2026
Apr 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
1Calderaforms
1Caldera Forms
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the...Show more
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less