CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ciphercoin 1Contact Form 7 Database Addon Jun 17, 2026 Jul 4, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Contact Form 7 Database Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tmpD’ parameter in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output e...Show more |
1Ciphercoin 1Contact Form 7 Database Addon Jun 17, 2026 Nov 21, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection |
1Ciphercoin 1Contact Form 7 Database Addon Jun 17, 2026 Dec 22, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.5.9). |
1Ciphercoin 1Contact Form 7 Database Addon Jun 17, 2026 Dec 22, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.6.1). |
1Ciphercoin 1Contact Form 7 Database Addon Jun 17, 2026 Mar 18, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files. |