Vulnerabilities and security researches forv-form v-form
Direction: ascendingAug 01, 2024
World first Lifetime free Form Builder for WordPress # CVE-2024-6770
- CVE, Research URL
- Date
- Jul 31, 2024
- Research Description
- The Lifetime free Drag & Drop Contact Form Builder for WordPress VForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Dec 15, 2024
World first Lifetime free Form Builder for WordPress # CVE-2024-54302
- CVE, Research URL
- Date
- Dec 13, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Reflected XSS.This issue affects VForm: from n/a through 3.0.0.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jan 26, 2025
World first Lifetime free Form Builder for WordPress # CVE-2025-24604
- CVE, Research URL
- Date
- Jan 24, 2025
- Research Description
- Missing Authorization vulnerability in Vikas Ratudi VForm allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects VForm: from n/a through 3.0.5.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Apr 03, 2025
World first Lifetime free Form Builder for WordPress # CVE-2025-30778
- CVE, Research URL
- Date
- Apr 02, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Reflected XSS. This issue affects VForm: from n/a through 3.1.9.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Apr 24, 2025
World first Lifetime free Form Builder for WordPress # CVE-2025-46250
- CVE, Research URL
- Date
- Apr 22, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Stored XSS. This issue affects VForm: from n/a through 3.1.14.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable