Extension WordPress
Vulnérabilités Google Forms
Cette page rassemble les failles publiées pour Google Forms, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Google Forms
5 fiches
Google Forms <= 0.95 – Authenticated (Admin+) Stored Cross-Site Scripting
The Google Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 0.95 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers…
*-0.95
Non indiqué
03/11/2022
Google Forms <= 0.93 – Remote Code Execution
The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.
[*, 0.94)
0.94
08/05/2018
Google Forms < 0.92 – Unauthenticated Server Side Request Forgery
The Google Forms plugin for WordPress is vulnerable to Server Side Request Forgery in versions before 0.92. This allowed Unauthenticated attackers to proxy requests through the plugin to an attacker-controlled host, which could also lead to a reflected…
[*, 0.92)
0.92
20/01/2018
Google Forms <= 0.90 – Unauthenticated PHP Object injection
The Google Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.90 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object. This vulnerability was confirmed to…
[*, 0.91)
0.91
07/01/2017
Google Forms < 0.85 – Cross-Site Scripting
The Google Forms plugin for WordPress is vulnerable to Cross-Site Scripting via the 'page' parameter in versions before 0.85 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts…
[*, 0.85)
0.85
14/07/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.