Extension WordPress

Vulnérabilités cformsII

Cette page rassemble les failles publiées pour cformsII, leurs plages de versions affectées et les correctifs signalés dans la base locale.

13Vulnérabilités
2Critiques
13Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de cformsII

13 fiches

CVE-2026-39436 Moyenne · 4,3
cformsII

cformsII <= 15.1.3 – Cross-Site Request Forgery

The cformsII plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 15.1.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to…

Versions affectées

*-15.1.3

Correctif

15.1.4

Publication

25/05/2026

CVE-2023-25449 Moyenne · 4,3
cformsII

cformsII <= 15.0.4 – Cross-Site Request Forgery leading to Settings Updates

The cformsII plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 15.0.4. This is due to missing or incorrect nonce validation in the 'cforms-options.php', 'cforms-global-settings.php', 'cforms-corrupted.php' files. This makes it possible for…

Versions affectées

*-15.0.4

Correctif

15.0.5

Publication

08/03/2023

CVE-2017-18559 Moyenne · 6,1
cformsII

cformsII <= 14.13.2 – Cross-Site Scripting

The cformsII plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 14.13.2 due to insufficient input sanitization and output escaping on the 'switchform', 'pickform', and 'noSub' parameters. This makes it possible for attackers…

Versions affectées

*-14.13.2

Correctif

14.13.3

Publication

28/04/2017

CVE-2017-18570 Élevée · 7,2
cformsII

cformsII <= 14.12.3 – Authenticated SQL Injection

The cformsII plugin for WordPress is vulnerable to generic SQL Injection via Delete Entries or Download Entries in versions up to, and including, 14.12.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

Versions affectées

[*, 14.13)

Correctif

14.13

Publication

24/04/2017

CVE-2014-9473 Critique · 9,8
cformsII

cformsII < 14.8 – Arbitrary File Upload

Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file…

Versions affectées

[*, 14.8)

Correctif

14.8

Publication

29/12/2014

Vulnérabilité Moyenne · 5,3
cformsII

CformsII <= 14.10.1 – CAPTCHA Bypass

The CformsII plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 14.10.1. This is due to the codes not being one-time use and improper verification of user-supplied data. This makes it possible for…

Versions affectées

*-14.10.1

Correctif

14.11

Publication

15/12/2010

CVE-2010-3977 Moyenne · 6,1
cformsII

CformsII <=11.5 – Cross-Site Scripting

Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cformsII(cforms 2) WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.

Versions affectées

*-11.5

Correctif

11.6.1

Publication

02/11/2010

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités