Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High1
Medium2
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2025-02-07

CVE-2024-7484 - Crm Perks Forms Plugin

The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'handle_uploaded_files' function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Crm Perks Forms

CVE-2024-7484

HIGH CVSS 7.2 2024-08-06
Threat Entry Updated 2024-11-21

CVE-2023-51536 - Crm Perks Forms Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms – WordPress Form Builder allows Stored XSS.This issue affects CRM Perks Forms – WordPress Form Builder: from n/a through 1.1.2.

PLUGIN Crm Perks Forms

CVE-2023-51536

MEDIUM CVSS 5.9 2024-02-01
Threat Entry Updated 2024-11-21

CVE-2023-2836 - Crm Perks Forms Plugin

The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Crm Perks Forms

CVE-2023-2836

MEDIUM CVSS 4.4 2023-05-31
Scroll to top