cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcontact-form-by-supsystic contact-form-by-supsystic

Direction: ascending
Jun 07, 2024

Contact Form by Supsystic # CVE-2021-24276

CVE, Research URL

CVE-2021-24276

Date
May 06, 2021
Research Description
The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
Affected versions
max 1.7.15.
Status
vulnerable

Contact Form by Supsystic # CVE-2023-2528

CVE, Research URL

CVE-2023-2528

Date
May 17, 2023
Research Description
The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.24. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.7.25.
Status
vulnerable

Contact Form by Supsystic # CVE-2023-45068

CVE, Research URL

CVE-2023-45068

Date
Oct 12, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Contact Form by Supsystic plugin <= 1.7.27 versions.
Affected versions
max 1.7.28.
Status
vulnerable
Oct 17, 2024

Contact Form by Supsystic # CVE-2024-48042

CVE, Research URL

CVE-2024-48042

Date
Oct 16, 2024
Research Description
Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Command Injection.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.28.
Affected versions
max 1.7.29.
Status
vulnerable
Oct 18, 2024

Contact Form by Supsystic # CVE-2024-48046

CVE, Research URL

CVE-2024-48046

Date
Oct 17, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Stored XSS.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.28.
Affected versions
max 1.7.29.
Status
vulnerable
Apr 17, 2025

Contact Form by Supsystic # CVE-2024-13452

CVE, Research URL

CVE-2024-13452

Date
Apr 16, 2025
Research Description
The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.29. This is due to missing or incorrect nonce validation on a saveAsCopy function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.7.30.
Status
vulnerable
Nov 11, 2025

Contact Form by Supsystic # CVE-2025-52753

CVE, Research URL

CVE-2025-52753

Date
Oct 22, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Reflected XSS.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.36.
Affected versions
max 1.8.0.
Status
vulnerable
Apr 14, 2026

Contact Form by Supsystic # CVE-2026-4257

CVE, Research URL

CVE-2026-4257

Date
Mar 31, 2026
Research Description
The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin using the Twig `Twig_Loader_String` template engine without sandboxing, combined with the `cfsPreFill` prefill functionality that allows unauthenticated users to inject arbitrary Twig expressions into form field values via GET parameters. This makes it possible for unauthenticated attackers to execute arbitrary PHP functions and OS commands on the server by leveraging Twig's `registerUndefinedFilterCallback()` method to register arbitrary PHP callbacks.
Affected versions
max 1.8.0.
Status
vulnerable
Jun 15, 2026

Contact Form by Supsystic # d971b68d077a008cccf535698bbb0b90c6bd7f82

Date
Feb 08, 2021
Research Description
Contact Form by Supsystic [contact-form-by-supsystic] < 1.7.7 WordPress Contact Form by Supsystic plugin <= 1.7.5 - SQL injection (SQLi) vulnerability SQL injection (SQLi) vulnerability found by Erik David Martin in WordPress Contact Form by Supsystic plugin (versions <= 1.7.5).
Affected versions
max 1.7.7.
Status
vulnerable

Contact Form by Supsystic # f1c090a2a0b46f722a35c4314edafcc14ee8956c

Date
Feb 08, 2021
Research Description
Contact Form by Supsystic [contact-form-by-supsystic] < 1.7.11 Contact Form by Supsystic <= 1.7.10 - SQL Injections The Contact Form by Supsystic plugin for WordPress is vulnerable to generic SQL Injection via the 'sidx' and 'sord' parameters in versions up to, and including, 1.7.10 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 1.7.11.
Status
vulnerable

Contact Form by Supsystic # a3146835-40f0-40ba-bde1-e2c0c9d0db97

Date
-
Research Description
Contact Form by Supsystic [contact-form-by-supsystic] < 1.7.7 Contact Form by Supsystic &lt; 1.7.7 - Authenticated Stored Cross-Site Scripting (XSS) The label field (Form name) was vulnerable to stored Cross-Site Scripting issue.
Affected versions
max 1.7.7.
Status
vulnerable

Contact Form by Supsystic # ee9cc8181b6fbf4a08f9bd0eb66012c33de76e3d

Date
Oct 28, 2021
Research Description
Contact Form by Supsystic [contact-form-by-supsystic] < 1.7.20 Contact Form by Supsystic < 1.7.20 - Authenticated (Admin+) Stored Cross-Site Scripting The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fields label in versions before 1.7.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with admin-level privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.7.20.
Status
vulnerable

Contact Form by Supsystic # 5a1bc23c2c564f4a131f42a73844d41644966517

Date
Feb 08, 2021
Research Description
Contact Form by Supsystic [contact-form-by-supsystic] < 1.7.7 WordPress Contact Form by Supsystic plugin <= 1.7.5 - Stored Cross-Site Scripting (XSS) vulnerability Stored Cross-Site Scripting (XSS) vulnerability found by Erik David Martin in WordPress Contact Form by Supsystic plugin (versions <= 1.7.5).
Affected versions
max 1.7.7.
Status
vulnerable

Contact Form by Supsystic # 79e00086-d0f0-4db2-9e3b-6d773fe73ef0

Date
-
Research Description
Contact Form by Supsystic [contact-form-by-supsystic] < 1.7.20 Contact Form by Supsystic &lt; 1.7.20 - Admin+ Stored Cross-Site Scripting The plugin does not sanitise and escape fields label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
Affected versions
max 1.7.20.
Status
vulnerable

Contact Form by Supsystic # 36559cb2-854e-4306-bae9-30c7965f84e0

Date
-
Research Description
Contact Form by Supsystic [contact-form-by-supsystic] < 1.7.11 Contact Form by Supsystic &lt; 1.7.11 - Authenticated SQL Injections The GET parameters sidx and sord were used in a SQL statement without being sanitised when searching for Forms in the dashboard, leading to an authenticated SQL Injection issues.
Affected versions
max 1.7.11.
Status
vulnerable
Aug 21, 2026

Contact Form by Supsystic # CVE-2026-73379

CVE, Research URL

CVE-2026-73379

Date
Aug 18, 2026
Research Description
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
Affected versions
max 1.10.0.
Status
vulnerable

Contact Form by Supsystic # CVE-2026-73378

CVE, Research URL

CVE-2026-73378

Date
Aug 18, 2026
Research Description
Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
Affected versions
max 1.10.0.
Status
vulnerable
Sep 06, 2026

Contact Form by Supsystic # CVE-2026-83625

CVE, Research URL

CVE-2026-83625

Date
Sep 05, 2026
Research Description
The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An unauthenticated attacker can first call the 'updateNonce' action — which is accessible without authentication due to its absence from the plugin's permission list — to obtain a valid nonce, then submit a contact form with a malicious payload in a spoofed IP header such as X-Forwarded-For.
Affected versions
max 1.10.3.
Status
vulnerable