cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forv-form v-form

Direction: ascending
Aug 01, 2024

World first Lifetime free Form Builder for WordPress # CVE-2024-6770

CVE, Research URL

CVE-2024-6770

Date
Jul 31, 2024
Research Description
The Lifetime free Drag & Drop Contact Form Builder for WordPress VForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Dec 15, 2024

World first Lifetime free Form Builder for WordPress # CVE-2024-54302

CVE, Research URL

CVE-2024-54302

Date
Dec 13, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Reflected XSS.This issue affects VForm: from n/a through 3.0.0.
Affected versions
Min -, max -.
Status
vulnerable
Jan 26, 2025

World first Lifetime free Form Builder for WordPress # CVE-2025-24604

CVE, Research URL

CVE-2025-24604

Date
Jan 24, 2025
Research Description
Missing Authorization vulnerability in Vikas Ratudi VForm allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects VForm: from n/a through 3.0.5.
Affected versions
Min -, max -.
Status
vulnerable
Apr 03, 2025

World first Lifetime free Form Builder for WordPress # CVE-2025-30778

CVE, Research URL

CVE-2025-30778

Date
Apr 02, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Reflected XSS. This issue affects VForm: from n/a through 3.1.9.
Affected versions
Min -, max -.
Status
vulnerable
Apr 24, 2025

World first Lifetime free Form Builder for WordPress # CVE-2025-46250

CVE, Research URL

CVE-2025-46250

Date
Apr 22, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Stored XSS. This issue affects VForm: from n/a through 3.1.14.
Affected versions
Min -, max -.
Status
vulnerable