cformsII <= 15.1.3 - Unauthenticated Stored Cross-Site Scripting
high
The cformsII plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 15.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...
- CVSS:
- 7.2
- Affected:
- up to 15.1.3
- Fixed in:
- 15.1.4
- Disclosed:
- Jun 1, 2026
CVE-2026-39435 on NVD →
cformsII <= 15.1.3 - Cross-Site Request Forgery
medium
The cformsII plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 15.1.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a...
- CVSS:
- 4.3
- Affected:
- up to 15.1.3
- Fixed in:
- 15.1.4
- Disclosed:
- May 25, 2026
CVE-2026-39436 on NVD →
cformsII [cforms2] < 15.0.7
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann CformsII allows Stored XSS.This issue affects CformsII: from n/a through 15.0.5.
- Affected:
- up to 15.0.7
- Fixed in:
- 15.0.7
- Disclosed:
- Mar 27, 2024
CVE-2024-22149 on NVD →
cformsII <= 15.0.6 - Unauthenticated Stored Cross-Site Scripting
high
The cformsII plugin for WordPress is vulnerable to stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 15.0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whe...
- CVSS:
- 7.2
- Affected:
- up to 15.0.6
- Fixed in:
- 15.0.7
- Disclosed:
- Jan 15, 2024
CVE-2024-22149 on NVD →
cformsII [cforms2] < 15.0.7
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a through 15.0.5.
- Affected:
- up to 15.0.7
- Fixed in:
- 15.0.7
- Disclosed:
- Jan 8, 2024
CVE-2023-52203 on NVD →
cformsII <= 15.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The cformsII plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 15.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitra...
- CVSS:
- 4.4
- Affected:
- up to 15.0.6
- Fixed in:
- 15.0.7
- Disclosed:
- Jan 3, 2024
CVE-2023-52203 on NVD →
cformsII [cforms2] < 15.0.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions.
- Affected:
- up to 15.0.5
- Fixed in:
- 15.0.5
- Disclosed:
- Jun 15, 2023
CVE-2023-25449 on NVD →
cformsII <= 15.0.4 - Cross-Site Request Forgery leading to Settings Updates
medium
The cformsII plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 15.0.4. This is due to missing or incorrect nonce validation in the 'cforms-options.php', 'cforms-global-settings.php', 'cforms-corrupted.php' files. This makes it possible for unauthenticated attackers to up...
- CVSS:
- 4.3
- Affected:
- up to 15.0.4
- Fixed in:
- 15.0.5
- Disclosed:
- Mar 8, 2023
CVE-2023-25449 on NVD →
cformsII [cforms2] < 14.6.10
unknown
[en] The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
- Affected:
- up to 14.6.10
- Fixed in:
- 14.6.10
- Disclosed:
- Aug 22, 2019
CVE-2015-9333 on NVD →
cformsII [cforms2] < 14.13
unknown
[en] The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.
- Affected:
- up to 14.13
- Fixed in:
- 14.13
- Disclosed:
- Aug 22, 2019
CVE-2017-18570 on NVD →
cformsII [cforms2] < 10.2
unknown
[en] The cforms2 plugin before 10.2 for WordPress has XSS.
- Affected:
- up to 10.2
- Fixed in:
- 10.2
- Disclosed:
- Aug 22, 2019
CVE-2014-10392 on NVD →
cformsII [cforms2] < 10.5
unknown
[en] The cforms2 plugin before 10.5 for WordPress has XSS.
- Affected:
- up to 10.5
- Fixed in:
- 10.5
- Disclosed:
- Aug 22, 2019
CVE-2014-10393 on NVD →
cformsII [cforms2] < 13.2
unknown
[en] The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.
- Affected:
- up to 13.2
- Fixed in:
- 13.2
- Disclosed:
- Aug 21, 2019
CVE-2014-10377 on NVD →
cformsII [cforms2] < 14.13.3
unknown
[en] The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.
- Affected:
- up to 14.13.3
- Fixed in:
- 14.13.3
- Disclosed:
- Aug 21, 2019
CVE-2017-18559 on NVD →
cformsII [cforms2] < 15.0.2
unknown
[en] The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.
- Affected:
- up to 15.0.2
- Fixed in:
- 15.0.2
- Disclosed:
- Aug 20, 2019
CVE-2019-15238 on NVD →
CformsII <= 15.0.1 - Unauthenticated HTML Injection & Cross-Site Request Forgery
high
The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.
- CVSS:
- 8.8
- Affected:
- up to 15.0.2
- Fixed in:
- 15.0.2
- Disclosed:
- Aug 12, 2019
CVE-2019-15238 on NVD →
cformsII [cforms2] < 15.0.2
unknown
Unauthenticated HTML Injection & Cross-Site Request Forgery (CSRF) vulnerabilities found by Jerome Bruandet (Nintechnet) in WordPress CformsII plugin (versions <= 15.0.1).
- Affected:
- up to 15.0.2
- Fixed in:
- 15.0.2
- Disclosed:
- Aug 12, 2019
cformsII <= 14.13.2 - Cross-Site Scripting
medium
The cformsII plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 14.13.2 due to insufficient input sanitization and output escaping on the 'switchform', 'pickform', and 'noSub' parameters. This makes it possible for attackers to inject arbitrary web scripts that execute in a vic...
- CVSS:
- 6.1
- Affected:
- up to 14.13.2
- Fixed in:
- 14.13.3
- Disclosed:
- Apr 28, 2017
CVE-2017-18559 on NVD →
cformsII <= 14.12.3 - Authenticated SQL Injection
high
The cformsII plugin for WordPress is vulnerable to generic SQL Injection via Delete Entries or Download Entries in versions up to, and including, 14.12.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for highly-privilege...
- CVSS:
- 7.2
- Affected:
- up to 14.13
- Fixed in:
- 14.13
- Disclosed:
- Apr 24, 2017
CVE-2017-18570 on NVD →
cformsII < 14.6.10 - SQL Injection
critical
The cforms2 plugin before 14.6.10 for WordPress has SQL injection via several parameters.
- CVSS:
- 9.8
- Affected:
- up to 14.6.10
- Fixed in:
- 14.6.10
- Disclosed:
- Apr 11, 2015
CVE-2015-9333 on NVD →
cformsII [cforms2] < 14.8
unknown
[en] Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file via a direct request to the file in the defa...
- Affected:
- up to 14.8
- Fixed in:
- 14.8
- Disclosed:
- Jan 8, 2015
CVE-2014-9473 on NVD →
cformsII < 14.8 - Arbitrary File Upload
critical
Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file via a direct request to the file in the default u...
- CVSS:
- 9.8
- Affected:
- up to 14.8
- Fixed in:
- 14.8
- Disclosed:
- Dec 29, 2014
CVE-2014-9473 on NVD →
cformsII <= 13.1 - Cross-Site Scripting
medium
The cforms II(2) plugin before 13.2 for WordPress has XSS in lib_ajax.php.
- CVSS:
- 6.1
- Affected:
- up to 13.1
- Fixed in:
- 13.2
- Disclosed:
- Oct 16, 2014
CVE-2014-10377 on NVD →
CformsII <= 14.10.1 - CAPTCHA Bypass
medium
The CformsII plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 14.10.1. This is due to the codes not being one-time use and improper verification of user-supplied data. This makes it possible for unauthenticated attackers to bypass the Captcha Verification.
- CVSS:
- 5.3
- Affected:
- up to 14.10.1
- Fixed in:
- 14.11
- Disclosed:
- Dec 15, 2010
cformsII [cforms2] < 14.11
unknown
The CformsII plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 14.10.1. This is due to the codes not being one-time use and improper verification of user-supplied data. This makes it possible for unauthenticated attackers to bypass the Captcha Verification.
- Affected:
- up to 14.11
- Fixed in:
- 14.11
- Disclosed:
- Dec 15, 2010
CformsII <=11.5 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cformsII(cforms 2) WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
- CVSS:
- 6.1
- Affected:
- up to 11.5
- Fixed in:
- 11.6.1
- Disclosed:
- Nov 2, 2010
CVE-2010-3977 on NVD →
cformsII [cforms2] < 14.11
unknown
The cformsII plugin (slug: cforms) and its fork (slug: cforms2) have a CAPTCHA Bypass vulnerability. The MD5 hash for matching the answer is sent with the forms and so it can be overwritten. This is fixed in the fork (cforms2) with version 14.11 (see changelog for confirmation). The original delicious:days version (cfo...
- Affected:
- up to 14.11
- Fixed in:
- 14.11
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database