Extension WordPress

Vulnérabilités Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress

Cette page rassemble les failles publiées pour Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
1Critiques
5Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress

5 fiches

CVE-2024-35678 Critique · 9,9
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress

Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress <= 1.7.2 – Authenticated (Author+) SQL Injection

The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.7.2 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-1.7.2

Correctif

1.7.3

Publication

05/06/2024

CVE-2023-36508 Élevée · 7,2
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress

Contact Form to DB by BestWebSoft <= 1.7.1 – Authenticated (Administrator+) SQL Injection via 's'

The Contact Form to DB by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in versions up to, and including, 1.7.1 due to insufficient escaping on the user supplied parameter and lack of…

Versions affectées

*-1.7.1

Correctif

1.7.2

Publication

23/06/2023

CVE-2023-29096 Élevée · 8,8
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress

Contact Form to DB by BestWebSoft <= 1.7.0 – Authenticated (Contributor+) SQL Injection via cntctfrmtdb_department

The Contact Form to DB by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the cntctfrmtdb_department parameter in versions up to, and including, 1.7.0 due to insufficient escaping on the user supplied parameter and lack of…

Versions affectées

*-1.7.0

Correctif

1.7.1

Publication

17/04/2023

Vulnérabilité Moyenne · 6,1
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress

Contact Form to DB <= 1.7.0 – Multiple Cross-Site Scripting

The Contact Form to DB plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web…

Versions affectées

*-1.7.0

Correctif

1.7.1

Publication

14/04/2023

CVE-2017-18492 Moyenne · 6,1
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress

Contact Form to DB <= 1.5.6 – Multiple Cross-Site Scripting

The Contact Form to DB plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web…

Versions affectées

*-1.5.6

Correctif

1.5.7

Publication

12/04/2017

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités