Extension WordPress
Vulnérabilités Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent
Cette page rassemble les failles publiées pour Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent
14 fiches
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-1.1.13
1.1.17
30/04/2026
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent <= 1.2.3 – Authenticated (Subscriber+) SQL Injection
The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.3 due to insufficient escaping on the user supplied parameter and…
*-1.2.3
1.2.4
24/02/2026
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent 0.5.4 – 1.2.1 – Missing Authorization to Authenticated (Subscriber+) Information Exposure and Privilege Escalation
The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to unauthorized access of data that leads to privilege escalation due to a missing capability check on the get_table_data() function…
0.5.4-1.2.1
1.2.2
18/02/2026
Tablesome <= 1.2.8 – Missing Authorization
The Tablesome plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-1.2.8
1.2.9
26/01/2026
Tablesome <= 1.1.35.1 – Missing Authorization
The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.35.1.…
*-1.1.35.1
1.1.35.2
22/12/2025
Tablesome <= 1.1.35.1 – Authenticated (Subscriber+) Information Exposure
The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.35.1. This makes it possible for authenticated attackers, with…
*-1.1.35.1
1.1.35.2
22/12/2025
Tablesome <= 1.1.34 – Missing Authorization
The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.34.…
*-1.1.34
1.1.35.1
05/12/2025
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent <= 1.1.32 – Unauthenticated Arbitrary File Upload
The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image_from_external_url() function in all versions up to, and…
*-1.1.32
1.3.33
31/10/2025
Table & Contact Form 7 Database – Tablesome <= 1.0.33 – Unauthenticated Sensitive Information Exposure
The Tablesome – Responsive Table, Woocommerce Automation, Email Log, Form Automation – Contact Form 7, Elementor, WPForms, Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.33 due to insufficient…
*-1.0.33
1.0.34
04/07/2024
Table & Contact Form 7 Database – Tablesome <= 1.0.25 – Cross-Site Request Forgery
The Table & Contact Form 7 Database – Tablesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.25. This is due to missing or incorrect nonce validation on the publish_table() function.…
*-1.0.25
1.0.26
10/04/2024
Table & Contact Form 7 Database – Tablesome <= 1.0.27 – Reflected Cross-Site Scripting
The Table & Contact Form 7 Database – Tablesome plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.27 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.0.27
1.0.28
16/03/2024
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-1.0.14
1.0.15
18/07/2023
Tablesome <= 1.0.8 – Reflected Cross-Site Scripting
The Tablesome plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via unescaped URLs in versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
[*, 1.0.9)
1.0.9
19/04/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 0.6.7)
0.6.7
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.