cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forquillforms quillforms

Direction: ascending
Jun 07, 2024

Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation # 02d057a552f114004c3599076a235cd5fa23cd8e

Date
Oct 24, 2023
Research Description
Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation Form on WordPress [quillforms] < 3.4.0 WordPress Quill Forms Plugin <= 3.3.0 is vulnerable to Broken Access Control No patched version is available. Abdi Pranata discovered and reported this Broken Access Control vulnerability in WordPress Quill Forms Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has not been known to be fixed yet.
Affected versions
max 3.4.0.
Status
vulnerable
Jun 10, 2024

Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation # CVE-2023-46610

CVE, Research URL

CVE-2023-46610

Date
Jan 02, 2025
Research Description
Missing Authorization vulnerability in Mohamed Magdy Quill Forms quillforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quill Forms: from n/a through <= 3.3.0.
Affected versions
max 3.4.0.
Status
vulnerable
Oct 03, 2024

Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation # CVE-2024-47393

CVE, Research URL

CVE-2024-47393

Date
Oct 05, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mohamed Magdy Quill Forms quillforms allows Stored XSS.This issue affects Quill Forms: from n/a through <= 3.7.0.
Affected versions
max 3.8.0.
Status
vulnerable
Jan 08, 2025

Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation # CVE-2024-11826

CVE, Research URL

CVE-2024-11826

Date
Jan 07, 2025
Research Description
The Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation Form on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quillforms-popup' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 4.0.0.
Status
vulnerable
Aug 18, 2026

Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation # CVE-2026-75091

CVE, Research URL

CVE-2026-75091

Date
Aug 18, 2026
Research Description
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 5.7.1.
Status
vulnerable