CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Contact Form Submissions Project 1Contact Form Submissions Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker c...Show more |
1Contact Form Submissions Project 1Contact Form Submissions Jun 17, 2026 Mar 18, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf7_contact_form GET parameter when submitting a filter request as a high privilege user (admin+) |