plugin

Cforms Vulnerabilities

6 known security issues reported for the Cforms WordPress plugin. Most recent disclosed Oct 15, 2014.

2 medium

Running Cforms on your site? Check whether your installed version is affected.

Scan your site free

cformsII <= 10.4 - Cross-Site Scripting

medium

The cforms2 plugin before 10.5 for WordPress has XSS.

CVSS:
6.1
Affected:
up to 10.5
Fixed in:
10.5
Disclosed:
Oct 15, 2014

CVE-2014-10393 on NVD →

Cforms <= 10.1 - Cross-Site Scripting

medium

The Cforms plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 10.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 10.1
Fixed in:
10.2
Disclosed:
Oct 15, 2014

CVE-2014-10392 on NVD →

cformsII – contact form [cforms] < 11.6.1 (closed)

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.

Affected:
up to 11.6.1
Fixed in:
11.6.1
Disclosed:
Nov 3, 2010

CVE-2010-3977 on NVD →

cformsII – contact form [cforms] <= 7.3 (closed)

unknown

[en] PHP remote file inclusion vulnerability in cforms-css.php in Oliver Seidel cforms (contactforms), a Wordpress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the tm parameter. NOTE: CVE disputes this issue for 7.3, since there is no tm parameter, and the code exits with a fatal error due...

Affected:
up to 7.3
Fixed in:
7.3
Disclosed:
Feb 4, 2008

CVE-2008-0560 on NVD →

cformsII – contact form [cforms] <= 10.1 (unfixed + closed)

unknown
Affected:
up to 10.1
Fix:
No patched version reported

cformsII – contact form [cforms] <= 10.1 (unfixed + closed)

unknown

The cformsII plugin (slug: cforms) and its fork (slug: cforms2) have a CAPTCHA Bypass vulnerability. The MD5 hash for matching the answer is sent with the forms and so it can be overwritten. This is fixed in the fork (cforms2) with version 14.11 (see changelog for confirmation). The original delicious:days version (cfo...

Affected:
up to 10.1
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database