cleantalk
Vulnerabilities and Security Researches

Contact Form Email, CVE-2025-10019

CVE, Research URL

CVE-2025-10019

Application

Contact Form Email

Published on
Dec 18, 2025
Research Description
Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.60.
Affected versions
max 1.3.60.
Status
vulnerable