← Back

Bitapps

bitapps

23 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Bit Form
bit_form
Bit Assist
bit_assist
File Manager
file_manager

CVEs (23)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bitapps
1Bit Assist
May 5, 2025
Aug 21, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered...Show more
The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Bitapps
1Contact Form Builder
Nov 21, 2024
Aug 14, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Contact Form Builder by Bit Form WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks ev...Show more
The Contact Form Builder by Bit Form WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Bitapps
1Bit Form
Jan 24, 2025
May 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server,...Show more
The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution.Show less