Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total33
Critical8
High8
Medium16
Reset
Showing 1-20 of 33 records
Threat Entry Updated 2026-07-13

CVE-2026-57423 - Contact Form 7 Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter allows Reflected XSS.This issue affects Message Filter for Contact Form 7: from n/a through

PLUGIN Contact Form 7

CVE-2026-57423

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57411 - Contact Form 7 Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman CF7 Views – Complete Entry Management for Contact Form 7 cf7-views allows DOM-Based XSS.This issue affects CF7 Views – Complete Entry Management for Contact Form 7: from n/a through

PLUGIN Contact Form 7

CVE-2026-57411

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-06-17

CVE-2026-42728 - Contact Form 7 Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows Stored XSS.This issue affects HT Contact Form 7: from n/a through

PLUGIN Contact Form 7

CVE-2026-42728

HIGH CVSS 7.1 2026-05-27
Threat Entry Updated 2026-06-17

CVE-2026-39707 - Contact Form 7 Plugin

Missing Authorization vulnerability in ZealousWeb Accept PayPal Payments using Contact Form 7 contact-form-7-paypal-extension allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accept PayPal Payments using Contact Form 7: from n/a through

PLUGIN Contact Form 7

CVE-2026-39707

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-06-17

CVE-2026-32527 - Contact Form 7 Plugin

Missing Authorization vulnerability in CRM Perks WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-insightly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through

PLUGIN Contact Form 7

CVE-2026-32527

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32496 - Contact Form 7 Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NYSL Spam Protect for Contact Form 7 wp-contact-form-7-spam-blocker allows Path Traversal.This issue affects Spam Protect for Contact Form 7: from n/a through

PLUGIN Contact Form 7

CVE-2026-32496

MEDIUM CVSS 6.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25430 - Contact Form 7 Plugin

Missing Authorization vulnerability in CRM Perks Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms cf7-mailchimp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through

PLUGIN Contact Form 7

CVE-2026-25430

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32460 - Contact Form 7 Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through

PLUGIN Contact Form 7

CVE-2026-32460

MEDIUM CVSS 6.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-24945 - Contact Form 7 Plugin

Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through

PLUGIN Contact Form 7

CVE-2026-24945

MEDIUM CVSS 5.3 2026-02-03
Threat Entry Updated 2026-01-23

CVE-2025-14457 - Contact Form 7 Plugin

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files when the "Send attachments as links" setting is enabled.

PLUGIN Contact Form 7

CVE-2025-14457

LOW CVSS 3.7 2026-01-15
Threat Entry Updated 2026-01-08

CVE-2025-14842 - Contact Form 7 Plugin

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files with a dangerous type in all versions up to, and including, 1.3.9.2. This is due to the plugin not blocking .phar and .svg files. This makes it possible for unauthenticated attackers to upload arbitrary .phar or .svg files containing malicious PHP or JavaScript code. Malicious PHP code can be used to achieve remote code execution on the server via direct file access, if the server is configured to execute…

PLUGIN Contact Form 7

CVE-2025-14842

MEDIUM CVSS 6.1 2026-01-07
Scroll to top