codedropz records
15 published records for vendor codedropz.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 6.7%
- Pre-auth RCE
- 5
- With a fix record
- 20%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-502 Deserialization of Untrusted Data1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-73 External Control of File Name or Path1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
63This week | CVE-2020-12800Weaponized | The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code excodedropz · drag and drop multiple file upload - contact form 7 · CWE-434 | Critical9.8 | — | 78.6% | Jun 8, 2020 |
41Plan | CVE-2025-3515Proof of concept | Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checkscodedropz · drag and drop multiple file upload - contact form 7 · CWE-434 | Critical9.8 | — | 5.8% | Jun 17, 2025 |
40Plan | CVE-2023-1112Proof of concept | Drag and Drop Multiple File Upload Contact Form 7 admin-ajax.php path traversalcodedropz · drag and drop multiple file upload - contact form 7 · CWE-23 | Critical9.8 | — | 3.0% | Mar 1, 2023 |
40Plan | CVE-2023-5822No exploit | Drag and Drop Multiple File Upload - Contact Form 7 <= 1.3.7.3 - Unauthenticated Arbitrary File Uploadcodedropz · drag and drop multiple file upload - contact form 7 · CWE-434 | Critical9.8 | — | 1.8% | Nov 22, 2023 |
39Monitor | CVE-2022-45377No exploit | WordPress Drag and Drop Multiple File Upload for WooCommerce Plugin <= 1.0.8 is vulnerable to Multiple Vulnerabilitiescodedropz · drag and drop multiple file upload for woocommerce · CWE-434 | Critical9.8 | — | 0.6% | Dec 21, 2023 |
36Monitor | CVE-2024-12267No exploit | Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletioncodedropz · drag and drop multiple file upload - contact form 7 · CWE-73 | Critical9.1 | — | 0.3% | Jan 31, 2025 |
35Monitor | CVE-2025-2328No exploit | Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File Deletioncodedropz · drag and drop multiple file upload - contact form 7 · CWE-22 | High8.8 | — | 1.1% | Mar 28, 2025 |
35Monitor | CVE-2025-2485No exploit | Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletioncodedropz · drag and drop multiple file upload - contact form 7 · CWE-502 | High8.8 | — | 0.6% | Mar 28, 2025 |
35Monitor | CVE-2022-45364No exploit | WordPress Drag and Drop Multiple File Upload – Contact Form 7 Plugin <= 1.3.6.5 is vulnerable to Cross Site Request Forgery (CSRF)codedropz · drag and drop multiple file upload - contact form 7 · CWE-352 | High8.8 | — | 0.2% | May 24, 2023 |
30Monitor | CVE-2024-3717No exploit | Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposurecodedropz · drag and drop multiple file upload - contact form 7 · CWE-922 | High7.5 | — | 0.7% | May 2, 2024 |
29Monitor | CVE-2025-14457No exploit | Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletioncodedropz · contact form 7 · CWE-862 | High7.4 | — | 0.2% | Jan 15, 2026 |
25Monitor | CVE-2022-0595Proof of concept | Drag and Drop Multiple File Upload - Contact Form 7 < 1.3.6.3 - Unauthenticated Stored XSScodedropz · drag and drop multiple file upload - contact form 7 · CWE-79 | Medium5.4 | — | 13.6% | Mar 28, 2022 |
24Monitor | CVE-2023-1282No exploit | Drag and Drop Multiple File Upload PRO - Reflected Cross-Site Scriptingcodedropz · drag and drop multiple file upload - contact form 7 · CWE-79 | Medium6.1 | — | 0.5% | Apr 17, 2023 |
21Monitor | CVE-2023-4821No exploit | Drag and Drop Multiple File Upload < 1.1.1 - Unauthenticated Stored Cross-Site Scriptingcodedropz · drag and drop multiple file uploader · CWE-79 | Medium5.4 | — | 0.4% | Oct 16, 2023 |
17Monitor | CVE-2022-3282No exploit | Drag and Drop Multiple File Upload < 1.3.6.5 - File Upload Size Limit Bypasscodedropz · drag and drop multiple file upload - contact form 7 · CWE-639 | Medium4.3 | — | 0.6% | Oct 17, 2022 |
- CVE-2020-1280063This week
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code ex
CriticalCVSS 9.8WeaponizedEPSS 79%codedropz · drag and drop multiple file upload - contact form 7Jun 8, 2020
- CVE-2025-351541Plan
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
CriticalCVSS 9.8Proof of conceptEPSS 6%codedropz · drag and drop multiple file upload - contact form 7Jun 17, 2025
- CVE-2023-111240Plan
Drag and Drop Multiple File Upload Contact Form 7 admin-ajax.php path traversal
CriticalCVSS 9.8Proof of conceptEPSS 3%codedropz · drag and drop multiple file upload - contact form 7Mar 1, 2023
- CVE-2023-582240Plan
Drag and Drop Multiple File Upload - Contact Form 7 <= 1.3.7.3 - Unauthenticated Arbitrary File Upload
CriticalCVSS 9.8No exploitEPSS 2%codedropz · drag and drop multiple file upload - contact form 7Nov 22, 2023
- CVE-2022-4537739Monitor
WordPress Drag and Drop Multiple File Upload for WooCommerce Plugin <= 1.0.8 is vulnerable to Multiple Vulnerabilities
CriticalCVSS 9.8No exploitEPSS 1%codedropz · drag and drop multiple file upload for woocommerceDec 21, 2023
- CVE-2024-1226736Monitor
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletion
CriticalCVSS 9.1No exploitEPSS 0%codedropz · drag and drop multiple file upload - contact form 7Jan 31, 2025
- CVE-2025-232835Monitor
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File Deletion
HighCVSS 8.8No exploitEPSS 1%codedropz · drag and drop multiple file upload - contact form 7Mar 28, 2025
- CVE-2025-248535Monitor
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion
HighCVSS 8.8No exploitEPSS 1%codedropz · drag and drop multiple file upload - contact form 7Mar 28, 2025
- CVE-2022-4536435Monitor
WordPress Drag and Drop Multiple File Upload – Contact Form 7 Plugin <= 1.3.6.5 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%codedropz · drag and drop multiple file upload - contact form 7May 24, 2023
- CVE-2024-371730Monitor
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposure
HighCVSS 7.5No exploitEPSS 1%codedropz · drag and drop multiple file upload - contact form 7May 2, 2024
- CVE-2025-1445729Monitor
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletion
HighCVSS 7.4No exploitEPSS 0%codedropz · contact form 7Jan 15, 2026
- CVE-2022-059525Monitor
Drag and Drop Multiple File Upload - Contact Form 7 < 1.3.6.3 - Unauthenticated Stored XSS
MediumCVSS 5.4Proof of conceptEPSS 14%codedropz · drag and drop multiple file upload - contact form 7Mar 28, 2022
- CVE-2023-128224Monitor
Drag and Drop Multiple File Upload PRO - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%codedropz · drag and drop multiple file upload - contact form 7Apr 17, 2023
- CVE-2023-482121Monitor
Drag and Drop Multiple File Upload < 1.1.1 - Unauthenticated Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%codedropz · drag and drop multiple file uploaderOct 16, 2023
- CVE-2022-328217Monitor
Drag and Drop Multiple File Upload < 1.3.6.5 - File Upload Size Limit Bypass
MediumCVSS 4.3No exploitEPSS 1%codedropz · drag and drop multiple file upload - contact form 7Oct 17, 2022