Vulnerabilities (CVE)

Filtered by vendor Contact Form Submissions Project Subscribe
Filtered by product Contact Form Submissions
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0248 1 Contact Form Submissions Project 1 Contact Form Submissions 2022-05-01 4.3 MEDIUM 6.1 MEDIUM
The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker could perform Cross-Site Scripting attacks against admins viewing the malicious submission