funnelforms records
17 published records for vendor funnelforms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 5.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-862 Missing Authorization10
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-502 Deserialization of Untrusted Data1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-10587No exploit | Funnelforms Free <= 3.7.5.1 - Authenticated (Contributor+) PHP Object Injectionfunnelforms · interactive contact form and multi step form builder with drag & drop editor – funnelforms free · CWE-502 | High8.8 | — | 0.6% | Dec 3, 2024 |
28Monitor | CVE-2024-6311No exploit | Funnelforms Free <= 3.7.3.2 - Authenticated (Administrator+) Arbitrary File Uploadfunnelforms · funnelforms free · CWE-434 | High7.2 | — | 0.9% | Aug 28, 2024 |
26Monitor | CVE-2024-6312No exploit | Funnelforms Free <= 3.7.3.2 - Authenticated (Administrator+) Arbitrary File Deletionfunnelforms · funnelforms free · CWE-22 | Medium6.5 | — | 1.1% | Aug 28, 2024 |
26Monitor | CVE-2023-5990No exploit | Funnelforms Free < 3.4.2 - Form Deletion/Duplication via CSRFfunnelforms · funnelforms free · CWE-352 | Medium6.5 | — | 0.3% | Dec 4, 2023 |
24Monitor | CVE-2023-4950No exploit | Funnelforms Free < 3.4 Unauthenticated Stored Cross-Site Scriptingfunnelforms · funnelforms · CWE-79 | Medium6.1 | — | 0.5% | Oct 16, 2023 |
21Monitor | CVE-2024-7447No exploit | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary funnelforms · funnelforms free · CWE-862 | Medium5.3 | — | 0.4% | Aug 28, 2024 |
21Monitor | CVE-2024-5857No exploit | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary funnelforms · funnelforms free · CWE-862 | Medium5.3 | — | 0.3% | Aug 29, 2024 |
17Monitor | CVE-2023-5386No exploit | Funnelforms Free <= 3.4 - Missing Authorization to Arbitrary Post Deletionfunnelforms · funnelforms · CWE-862 | Medium4.3 | — | 0.4% | Nov 22, 2023 |
17Monitor | CVE-2023-5387No exploit | Funnelforms Free <= 3.4 - Missing Authorization to Enable/Disable Dark Modefunnelforms · funnelforms · CWE-862 | Medium4.3 | — | 0.4% | Nov 22, 2023 |
17Monitor | CVE-2023-5415No exploit | Funnelforms Free <= 3.4 - Missing Authorization to New Category Creationfunnelforms · funnelforms · CWE-862 | Medium4.3 | — | 0.4% | Nov 22, 2023 |
17Monitor | CVE-2023-5416No exploit | Funnelforms Free <= 3.4 - Missing Authorization to Category Deletionfunnelforms · funnelforms · CWE-862 | Medium4.3 | — | 0.4% | Nov 22, 2023 |
17Monitor | CVE-2023-5411No exploit | Funnelforms Free <= 3.4 - Missing Authorization to Post Modificationfunnelforms · funnelforms · CWE-862 | Medium4.3 | — | 0.4% | Nov 22, 2023 |
17Monitor | CVE-2023-5417No exploit | Funnelforms Free <= 3.4 - Missing Authorization to Category Updatefunnelforms · funnelforms · CWE-862 | Medium4.3 | — | 0.4% | Nov 22, 2023 |
17Monitor | CVE-2023-5419No exploit | Funnelforms Free <= 3.4 - Missing Authorization to Test Email Sendingfunnelforms · funnelforms · CWE-862 | Medium4.3 | — | 0.4% | Nov 22, 2023 |
17Monitor | CVE-2023-5385No exploit | Funnelforms Free <= 3.4 - Missing Authorization to Arbitrary Post Duplicationfunnelforms · funnelforms · CWE-862 | Medium4.3 | — | 0.4% | Nov 22, 2023 |
17Monitor | CVE-2023-5382No exploit | Funnelforms Free <= 3.4 - Cross-Site Request Forgery to Arbitrary Post Deletionfunnelforms · funnelforms · CWE-352 | Medium4.3 | — | 0.3% | Nov 22, 2023 |
17Monitor | CVE-2023-5383No exploit | Funnelforms Free <= 3.4 - Cross-Site Request Forgery to Arbitrary Post Duplicationfunnelforms · funnelforms · CWE-352 | Medium4.3 | — | 0.2% | Nov 22, 2023 |
- CVE-2024-1058735Monitor
Funnelforms Free <= 3.7.5.1 - Authenticated (Contributor+) PHP Object Injection
HighCVSS 8.8No exploitEPSS 1%funnelforms · interactive contact form and multi step form builder with drag & drop editor – funnelforms freeDec 3, 2024
- CVE-2024-631128Monitor
Funnelforms Free <= 3.7.3.2 - Authenticated (Administrator+) Arbitrary File Upload
HighCVSS 7.2No exploitEPSS 1%funnelforms · funnelforms freeAug 28, 2024
- CVE-2024-631226Monitor
Funnelforms Free <= 3.7.3.2 - Authenticated (Administrator+) Arbitrary File Deletion
MediumCVSS 6.5No exploitEPSS 1%funnelforms · funnelforms freeAug 28, 2024
- CVE-2023-599026Monitor
Funnelforms Free < 3.4.2 - Form Deletion/Duplication via CSRF
MediumCVSS 6.5No exploitEPSS 0%funnelforms · funnelforms freeDec 4, 2023
- CVE-2023-495024Monitor
Funnelforms Free < 3.4 Unauthenticated Stored Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%funnelforms · funnelformsOct 16, 2023
- CVE-2024-744721Monitor
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary
MediumCVSS 5.3No exploitEPSS 0%funnelforms · funnelforms freeAug 28, 2024
- CVE-2024-585721Monitor
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary
MediumCVSS 5.3No exploitEPSS 0%funnelforms · funnelforms freeAug 29, 2024
- CVE-2023-538617Monitor
Funnelforms Free <= 3.4 - Missing Authorization to Arbitrary Post Deletion
MediumCVSS 4.3No exploitEPSS 0%funnelforms · funnelformsNov 22, 2023
- CVE-2023-538717Monitor
Funnelforms Free <= 3.4 - Missing Authorization to Enable/Disable Dark Mode
MediumCVSS 4.3No exploitEPSS 0%funnelforms · funnelformsNov 22, 2023
- CVE-2023-541517Monitor
Funnelforms Free <= 3.4 - Missing Authorization to New Category Creation
MediumCVSS 4.3No exploitEPSS 0%funnelforms · funnelformsNov 22, 2023
- CVE-2023-541617Monitor
Funnelforms Free <= 3.4 - Missing Authorization to Category Deletion
MediumCVSS 4.3No exploitEPSS 0%funnelforms · funnelformsNov 22, 2023
- CVE-2023-541117Monitor
Funnelforms Free <= 3.4 - Missing Authorization to Post Modification
MediumCVSS 4.3No exploitEPSS 0%funnelforms · funnelformsNov 22, 2023
- CVE-2023-541717Monitor
Funnelforms Free <= 3.4 - Missing Authorization to Category Update
MediumCVSS 4.3No exploitEPSS 0%funnelforms · funnelformsNov 22, 2023
- CVE-2023-541917Monitor
Funnelforms Free <= 3.4 - Missing Authorization to Test Email Sending
MediumCVSS 4.3No exploitEPSS 0%funnelforms · funnelformsNov 22, 2023
- CVE-2023-538517Monitor
Funnelforms Free <= 3.4 - Missing Authorization to Arbitrary Post Duplication
MediumCVSS 4.3No exploitEPSS 0%funnelforms · funnelformsNov 22, 2023
- CVE-2023-538217Monitor
Funnelforms Free <= 3.4 - Cross-Site Request Forgery to Arbitrary Post Deletion
MediumCVSS 4.3No exploitEPSS 0%funnelforms · funnelformsNov 22, 2023
- CVE-2023-538317Monitor
Funnelforms Free <= 3.4 - Cross-Site Request Forgery to Arbitrary Post Duplication
MediumCVSS 4.3No exploitEPSS 0%funnelforms · funnelformsNov 22, 2023