Vulnerabilities (CVE)

Filtered by vendor Gvectors Subscribe
Filtered by product Wpforo Forum
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-47872 1 Gvectors 1 Wpforo Forum 2023-12-06 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team wpForo Forum allows Stored XSS.This issue affects wpForo Forum: from n/a through 2.2.3.
CVE-2023-2309 1 Gvectors 1 Wpforo Forum 2023-07-31 N/A 6.1 MEDIUM
The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.
CVE-2021-24406 1 Gvectors 1 Wpforo Forum 2021-07-09 5.8 MEDIUM 6.1 MEDIUM
The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands)
CVE-2018-11709 1 Gvectors 1 Wpforo Forum 2018-07-16 4.3 MEDIUM 6.1 MEDIUM
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.