Vulnerabilities and security researches forpiotnetforms piotnetforms
Direction: ascendingJun 07, 2024
Piotnet Forms # CVE-2023-51412
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 29, 2023
- Research Description
- Unrestricted Upload of File with Dangerous Type vulnerability in Piotnet Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.25.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Piotnet Forms # CVE-2023-6220
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 11, 2024
- Research Description
- The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'piotnetforms_ajax_form_builder' function in versions up to, and including, 1.0.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jun 10, 2024
Piotnet Forms # CVE-2023-51413
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 12, 2024
- Research Description
- Missing Authorization vulnerability in Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.29.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Apr 03, 2025
Piotnet Forms # CVE-2025-31793
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 01, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms allows Stored XSS. This issue affects Piotnet Forms: from n/a through 1.0.30.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Piotnet Forms # CVE-2025-31792
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 01, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms allows Stored XSS. This issue affects Piotnet Forms: from n/a through 1.0.30.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable