sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total25
Critical6
High5
Medium13
Reset
Showing 21-25 of 25 records
Threat Entry Updated 2026-06-17

Everest Forms - Server-Side Request Forgery (SSRF) (CVE-2024-1812)

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Everest Forms

CVE-2024-1812

HIGH CVSS 7.2 2024-04-09
Threat Entry Updated 2026-06-17

Everest Forms - Cross-Site Scripting (XSS) (CVE-2023-51695)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease! allows Stored XSS.This issue affects Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease!: from n/a through 2.0.4.1.

PLUGIN Everest Forms

CVE-2023-51695

MEDIUM CVSS 5.9 2024-02-01
Threat Entry Updated 2026-06-17

Everest Forms - SQL Injection (CVE-2019-13575)

A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php

PLUGIN Everest Forms

CVE-2019-13575

CRITICAL CVSS 9.8 2019-07-18