fluentforms records
19 published records for vendor fluentforms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 10.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-862 Missing Authorization2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-285 Improper Authorization1
- CWE-502 Deserialization of Untrusted Data1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2024-2771Proof of concept | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilegefluentforms · contact form · CWE-862 | Critical9.8 | — | 2.3% | May 18, 2024 |
39Monitor | CVE-2022-3463No exploit | FluentForm < 4.3.13 - CSV Injectionfluentforms · contact form · CWE-1236 | Critical9.8 | — | 1.3% | Nov 7, 2022 |
39Monitor | CVE-2023-24410No exploit | WordPress FluentForm Plugin <= 4.3.25 is vulnerable to SQL Injectionfluentforms · contact form · CWE-89 | Critical9.8 | — | 0.7% | Oct 31, 2023 |
36Monitor | CVE-2021-34620No exploit | CSRF in WP Fluent Forms < 3.6.67 allows stored XSS and Privilege Escalationfluentforms · contact form · CWE-79 | High8.8 | — | 2.6% | Jul 7, 2021 |
35Monitor | CVE-2024-4157Proof of concept | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via extractDynamicValuesfluentforms · contact form · CWE-502 | High8.8 | — | 0.7% | May 22, 2024 |
30Monitor | CVE-2024-2782Proof of concept | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulationfluentforms · contact form · CWE-862 | High7.5 | — | 1.2% | May 18, 2024 |
25Monitor | CVE-2024-4709No exploit | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Authenticated (Contributor+) Stored Cross-Site Scriptingfluentforms · contact form · CWE-79 | Medium6.4 | — | 0.4% | May 18, 2024 |
24Monitor | CVE-2024-9651No exploit | Contact Form Plugin by Fluent Forms < 5.2.1 - Admin+ Stored XSSfluentforms · contact form · CWE-79 | Medium6.1 | — | 0.4% | Dec 9, 2024 |
24Monitor | CVE-2024-10646No exploit | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subjectfluentforms · contact form · CWE-79 | Medium6.1 | — | 0.4% | Dec 14, 2024 |
21Monitor | CVE-2023-0546No exploit | FluentForms < 4.3.25 - Contributor+ Stored XSS via Custom HTML Form Fieldfluentforms · contact form · CWE-79 | Medium5.4 | — | 0.5% | Apr 10, 2023 |
21Monitor | CVE-2023-6957No exploit | Fluent Forms <= 5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scriptingfluentforms · contact form · CWE-79 | Medium5.4 | — | 0.4% | Mar 13, 2024 |
21Monitor | CVE-2024-6703No exploit | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Wefluentforms · contact form · CWE-79 | Medium5.4 | — | 0.3% | Jul 27, 2024 |
21Monitor | CVE-2024-2772No exploit | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.13 - Authenticated (Subscriber+) Stored Cross-Site Scriptingfluentforms · contact form · CWE-79 | Medium5.4 | — | 0.3% | May 18, 2024 |
19Monitor | CVE-2024-0618No exploit | Fluent Forms <= 5.1.5 - Authenticated(Administrator+) Stored Cross-Site Scripting via imported form titlefluentforms · contact form · CWE-79 | Medium4.8 | — | 0.5% | Jan 27, 2024 |
19Monitor | CVE-2024-9528No exploit | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scriptingfluentforms · contact form · CWE-79 | Medium4.8 | — | 0.4% | Oct 4, 2024 |
17Monitor | CVE-2024-5053No exploit | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - Missing Authorization to Authenticated (Subscriber+) Mailchimfluentforms · contact form · CWE-285 | Medium4.3 | — | 0.4% | Sep 1, 2024 |
17Monitor | CVE-2024-6520No exploit | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scriptingfluentforms · contact form · CWE-79 | Medium4.4 | — | 0.3% | Jul 27, 2024 |
17Monitor | CVE-2024-6521No exploit | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scriptingfluentforms · contact form · CWE-79 | Medium4.4 | — | 0.3% | Jul 27, 2024 |
17Monitor | CVE-2024-6518No exploit | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scriptingfluentforms · contact form · CWE-79 | Medium4.4 | — | 0.3% | Jul 27, 2024 |
- CVE-2024-277140Plan
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege
CriticalCVSS 9.8Proof of conceptEPSS 2%fluentforms · contact formMay 18, 2024
- CVE-2022-346339Monitor
FluentForm < 4.3.13 - CSV Injection
CriticalCVSS 9.8No exploitEPSS 1%fluentforms · contact formNov 7, 2022
- CVE-2023-2441039Monitor
WordPress FluentForm Plugin <= 4.3.25 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%fluentforms · contact formOct 31, 2023
- CVE-2021-3462036Monitor
CSRF in WP Fluent Forms < 3.6.67 allows stored XSS and Privilege Escalation
HighCVSS 8.8No exploitEPSS 3%fluentforms · contact formJul 7, 2021
- CVE-2024-415735Monitor
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via extractDynamicValues
HighCVSS 8.8Proof of conceptEPSS 1%fluentforms · contact formMay 22, 2024
- CVE-2024-278230Monitor
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation
HighCVSS 7.5Proof of conceptEPSS 1%fluentforms · contact formMay 18, 2024
- CVE-2024-470925Monitor
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 6.4No exploitEPSS 0%fluentforms · contact formMay 18, 2024
- CVE-2024-965124Monitor
Contact Form Plugin by Fluent Forms < 5.2.1 - Admin+ Stored XSS
MediumCVSS 6.1No exploitEPSS 0%fluentforms · contact formDec 9, 2024
- CVE-2024-1064624Monitor
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject
MediumCVSS 6.1No exploitEPSS 0%fluentforms · contact formDec 14, 2024
- CVE-2023-054621Monitor
FluentForms < 4.3.25 - Contributor+ Stored XSS via Custom HTML Form Field
MediumCVSS 5.4No exploitEPSS 0%fluentforms · contact formApr 10, 2023
- CVE-2023-695721Monitor
Fluent Forms <= 5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%fluentforms · contact formMar 13, 2024
- CVE-2024-670321Monitor
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Subscriber+) Stored Cross-Site Scripting via We
MediumCVSS 5.4No exploitEPSS 0%fluentforms · contact formJul 27, 2024
- CVE-2024-277221Monitor
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%fluentforms · contact formMay 18, 2024
- CVE-2024-061819Monitor
Fluent Forms <= 5.1.5 - Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title
MediumCVSS 4.8No exploitEPSS 1%fluentforms · contact formJan 27, 2024
- CVE-2024-952819Monitor
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scripting
MediumCVSS 4.8No exploitEPSS 0%fluentforms · contact formOct 4, 2024
- CVE-2024-505317Monitor
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - Missing Authorization to Authenticated (Subscriber+) Mailchim
MediumCVSS 4.3No exploitEPSS 0%fluentforms · contact formSep 1, 2024
- CVE-2024-652017Monitor
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting
MediumCVSS 4.4No exploitEPSS 0%fluentforms · contact formJul 27, 2024
- CVE-2024-652117Monitor
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting
MediumCVSS 4.4No exploitEPSS 0%fluentforms · contact formJul 27, 2024
- CVE-2024-651817Monitor
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting
MediumCVSS 4.4No exploitEPSS 0%fluentforms · contact formJul 27, 2024