jqueryform records
10 published records for vendor jqueryform.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-522 Insufficiently Protected Credentials1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
- CWE-502 Deserialization of Untrusted Data1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-9482No exploit | PHP FormMail Generator generates PHP code for standard web forms, and the code generated is vulnerable to authentication bypassjqueryform · php formmail generator · CWE-302 | Critical9.8 | — | 4.5% | Jul 13, 2018 |
40Plan | CVE-2016-9483No exploit | PHP FormMail Generator generates PHP code for standard web forms, and the code generated is vulnerable to unsafe deserialization of untrusted datajqueryform · php formmail generator · CWE-502 | Critical9.8 | — | 3.4% | Jul 13, 2018 |
40Plan | CVE-2016-9492No exploit | PHP forms generated using the PHP FormMail Generator are vulnerable to unrestricted upload of dangerous file typesjqueryform · php formmail generator · CWE-434 | Critical9.8 | — | 3.3% | Jul 13, 2018 |
40Plan | CVE-2022-24984No exploit | Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload jqueryform · jqueryform · CWE-434 | Critical9.8 | — | 2.6% | Feb 16, 2022 |
36Monitor | CVE-2022-24985No exploit | Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administrjqueryform · jqueryform | High8.8 | — | 2.3% | Feb 16, 2022 |
31Monitor | CVE-2016-9484No exploit | PHP FormMail Generator generates PHP code for standard web forms, and the code generated does not properly validate user input folder directories and is vulnerajqueryform · php formmail generator · CWE-22 | High7.5 | — | 4.4% | Jul 13, 2018 |
31Monitor | CVE-2022-24983No exploit | Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST respjqueryform · jqueryform · CWE-22 | High7.5 | — | 2.7% | Feb 16, 2022 |
26Monitor | CVE-2022-24982No exploit | Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext credentials of all other jqueryform · jqueryform · CWE-522 | Medium6.5 | — | 1.2% | Feb 16, 2022 |
24Monitor | CVE-2016-9493No exploit | PHP forms generated using the PHP FormMail Generator are vulnerable to stored cross-site scriptingjqueryform · php formmail generator · CWE-80 | Medium6.1 | — | 1.5% | Jul 13, 2018 |
24Monitor | CVE-2022-24981No exploit | A reflected cross-site scripting (XSS) vulnerability in forms generated by JQueryForm.com before 2022-02-05 allows remote attackers to injecjqueryform · jqueryform · CWE-79 | Medium6.1 | — | 1.0% | Feb 16, 2022 |
- CVE-2016-948240Plan
PHP FormMail Generator generates PHP code for standard web forms, and the code generated is vulnerable to authentication bypass
CriticalCVSS 9.8No exploitEPSS 4%jqueryform · php formmail generatorJul 13, 2018
- CVE-2016-948340Plan
PHP FormMail Generator generates PHP code for standard web forms, and the code generated is vulnerable to unsafe deserialization of untrusted data
CriticalCVSS 9.8No exploitEPSS 3%jqueryform · php formmail generatorJul 13, 2018
- CVE-2016-949240Plan
PHP forms generated using the PHP FormMail Generator are vulnerable to unrestricted upload of dangerous file types
CriticalCVSS 9.8No exploitEPSS 3%jqueryform · php formmail generatorJul 13, 2018
- CVE-2022-2498440Plan
Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload
CriticalCVSS 9.8No exploitEPSS 3%jqueryform · jqueryformFeb 16, 2022
- CVE-2022-2498536Monitor
Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administr
HighCVSS 8.8No exploitEPSS 2%jqueryform · jqueryformFeb 16, 2022
- CVE-2016-948431Monitor
PHP FormMail Generator generates PHP code for standard web forms, and the code generated does not properly validate user input folder directories and is vulnera
HighCVSS 7.5No exploitEPSS 4%jqueryform · php formmail generatorJul 13, 2018
- CVE-2022-2498331Monitor
Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST resp
HighCVSS 7.5No exploitEPSS 3%jqueryform · jqueryformFeb 16, 2022
- CVE-2022-2498226Monitor
Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext credentials of all other
MediumCVSS 6.5No exploitEPSS 1%jqueryform · jqueryformFeb 16, 2022
- CVE-2016-949324Monitor
PHP forms generated using the PHP FormMail Generator are vulnerable to stored cross-site scripting
MediumCVSS 6.1No exploitEPSS 2%jqueryform · php formmail generatorJul 13, 2018
- CVE-2022-2498124Monitor
A reflected cross-site scripting (XSS) vulnerability in forms generated by JQueryForm.com before 2022-02-05 allows remote attackers to injec
MediumCVSS 6.1No exploitEPSS 1%jqueryform · jqueryformFeb 16, 2022