Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2024-11-21

CVE-2022-0879 - Caldera Forms Plugin

The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting

PLUGIN Caldera Forms

CVE-2022-0879

MEDIUM CVSS 6.1 2022-04-18
Threat Entry Updated 2024-11-21

CVE-2021-24896 - Caldera Forms Plugin

The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Caldera Forms

CVE-2021-24896

MEDIUM CVSS 4.8 2021-12-13
Scroll to top