cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcontact-forms contact-forms

Direction: descending
Jun 16, 2026

WordPress Contact Forms by Cimatti # 2d669501ada3e5144b1df53e139e197bdea2364f

Date
Mar 27, 2023
Research Description
Contact Forms by Cimatti [contact-forms] < 1.5.5 WordPress Contact Forms by Cimatti <= 1.5.4 - Unauthenticated Stored Cross-Site Scripting The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form parameters in versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.5.5.
Status
vulnerable
Jun 14, 2025

WordPress Contact Forms by Cimatti # CVE-2025-49069

CVE, Research URL

CVE-2025-49069

Date
Jun 03, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in cimatti Contact Forms by Cimatti contact-forms allows Cross Site Request Forgery.This issue affects Contact Forms by Cimatti: from n/a through <= 1.9.8.
Affected versions
max 1.9.9.
Status
vulnerable
Feb 02, 2025

WordPress Contact Forms by Cimatti # CVE-2024-12184

CVE, Research URL

CVE-2024-12184

Date
Feb 01, 2025
Research Description
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the accua_forms_download_submitted_file() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to download other user submitted forms.
Affected versions
max 1.9.5.
Status
vulnerable

WordPress Contact Forms by Cimatti # CVE-2023-35051

CVE, Research URL

CVE-2023-35051

Date
Dec 13, 2024
Research Description
Missing Authorization vulnerability in Cimatti Consulting Contact Forms by Cimatti allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Forms by Cimatti: from n/a through 1.5.7.
Affected versions
max 1.5.8.
Status
vulnerable
Nov 28, 2024

WordPress Contact Forms by Cimatti # CVE-2024-10521

CVE, Research URL

CVE-2024-10521

Date
Nov 27, 2024
Research Description
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to delete forms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.9.3.
Status
vulnerable
Jun 07, 2024

WordPress Contact Forms by Cimatti # CVE-2021-24744

CVE, Research URL

CVE-2021-24744

Date
Oct 25, 2021
Research Description
The WordPress Contact Forms by Cimatti WordPress plugin before 1.4.12 does not sanitise and escape the Form Title before outputting it in some admin pages. which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
Affected versions
max 1.4.12.
Status
vulnerable

WordPress Contact Forms by Cimatti # CVE-2023-28781

CVE, Research URL

CVE-2023-28781

Date
Apr 07, 2023
Research Description
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.
Affected versions
max 1.5.5.
Status
vulnerable

WordPress Contact Forms by Cimatti # CVE-2023-47230

CVE, Research URL

CVE-2023-47230

Date
Nov 13, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.6.0 versions.
Affected versions
max 1.6.1.
Status
vulnerable

WordPress Contact Forms by Cimatti # CVE-2024-30549

CVE, Research URL

CVE-2024-30549

Date
Apr 01, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cimatti Contact Forms by Cimatti contact-forms.This issue affects Contact Forms by Cimatti: from n/a through <= 1.8.0.
Affected versions
max 1.9.1.
Status
vulnerable

WordPress Contact Forms by Cimatti # CVE-2023-2563

CVE, Research URL

CVE-2023-2563

Date
Jun 13, 2023
Research Description
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.5.8.
Status
vulnerable

WordPress Contact Forms by Cimatti # CVE-2024-29117

CVE, Research URL

CVE-2024-29117

Date
Mar 19, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cimatti Consulting Contact Forms by Cimatti allows Stored XSS.This issue affects Contact Forms by Cimatti: from n/a through 1.7.0.
Affected versions
max 1.8.0.
Status
vulnerable

WordPress Contact Forms by Cimatti # CVE-2023-28789

CVE, Research URL

CVE-2023-28789

Date
Apr 07, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.
Affected versions
max 1.5.5.
Status
vulnerable