cleantalk
Vulnerabilities and Security Researches

CubeWP Forms – LeadGen & Contact Form, CVE-2024-47300

CVE, Research URL

CVE-2024-47300

Published on
Oct 06, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CubeWP CubeWP Forms – All-in-One Form Builder allows Stored XSS.This issue affects CubeWP Forms – All-in-One Form Builder: from n/a through 1.1.1.
Affected versions
max 1.1.2.
Status
vulnerable