Extension WordPress
Vulnérabilités Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms
Cette page rassemble les failles publiées pour Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms
7 fiches
HappyForms <= 1.26.12 – Authenticated (Admin+) Local File Inclusion
The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.26.12 via the happyforms_get_form_partial() function.…
*-1.26.12
1.26.13
09/07/2026
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms <= 1.26.13 – Unauthenticated PHP Object Injection
The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.26.13 via deserialization of untrusted input.…
*-1.26.13
1.26.14
04/06/2026
Happyforms <= 1.26.2 – Authenticated (Admin+) Stored Cross-Site Scripting
The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.2 due…
*-1.26.2
1.26.3
20/11/2024
Happyforms <= 1.26.0 – Authenticated (Author+) Stored Cross-Site Scripting
The Happyforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.26.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above,…
*-1.26.0
1.26.1
29/08/2024
Happyforms <= 1.25.10 – Missing Authorization
The Happyforms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in all versions up to, and including, 1.25.10. This makes it possible for unauthenticated attackers to perform unauthorized actions.
*-1.25.10
1.25.11
31/01/2024
Happyforms <= 1.25.9 – Reflected Cross-Site Scripting
The Form builder to get in touch with visitors, grow your email list and collect payments , Happyforms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.25.9 due to insufficient…
*-1.25.9
1.25.10
27/11/2023
Happyforms <= 1.21.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Blocks
The Happyforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ and 'anchor' block options in versions up to, and including, 1.21.1 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.21.1
1.22.0
13/01/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.