Ncrafts Formcraft vulnerabilities
11 known vulnerabilities affecting ncrafts/formcraft.
Total CVEs
11
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2025-0817MEDIUMCVSS 6.1fixed in 3.9.122025-02-18
CVE-2025-0817 [MEDIUM] CWE-79 CVE-2025-0817: The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads
The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.9.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG fil
nvd
CVE-2024-13783MEDIUMCVSS 4.3fixed in 3.9.122025-02-18
CVE-2024-13783 [MEDIUM] CWE-862 CVE-2024-13783: The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing cap
The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in formcraft-main.php in all versions up to, and including, 3.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export all plugin data which may contain sensitive information from form s
nvd
CVE-2023-47823MEDIUMCVSS 5.3≥ n/a, ≤ 1.2.72024-12-09
CVE-2023-47823 [MEDIUM] CWE-862 CVE-2023-47823: Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Ac
Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2.7.
cvelistv5nvd
CVE-2024-43157MEDIUMCVSS 4.3≥ n/a, ≤ 1.2.102024-11-01
CVE-2024-43157 [MEDIUM] CWE-862 CVE-2024-43157: Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Ac
Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2.10.
cvelistv5nvd
CVE-2023-2592HIGHCVSS 7.2fixed in 3.9.72023-06-27
CVE-2023-2592 [HIGH] CWE-89 CVE-2023-2592: The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before
The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
nvd
CVE-2023-22717MEDIUMCVSS 5.4≤ 1.2.6≥ n/a, ≤ 1.2.62023-05-15
CVE-2023-22717 [MEDIUM] CWE-79 CVE-2023-22717: Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in nCrafts FormCraft plugin <=
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in nCrafts FormCraft plugin <= 1.2.6 versions.
cvelistv5nvd
CVE-2022-1647MEDIUMCVSS 4.8fixed in 1.2.62022-06-08
CVE-2022-1647 [MEDIUM] CWE-79 CVE-2022-1647: The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high
The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
nvd
CVE-2017-18600MEDIUMCVSS 5.4≤ 3.2.312019-09-10
CVE-2017-18600 [MEDIUM] CWE-79 CVE-2017-18600: The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading
The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.
nvd
CVE-2019-15114HIGHCVSS 8.8fixed in 1.2.22019-08-16
CVE-2019-15114 [HIGH] CWE-352 CVE-2019-15114: The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
nvd
CVE-2019-5920HIGHCVSS 8.8≤ 1.2.1v1.2.1 and earlier2019-03-12
CVE-2019-5920 [HIGH] CWE-352 CVE-2019-5920: Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attacke
Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.
cvelistv5nvd
CVE-2013-7187HIGHCVSS 7.5PoC≤ 1.3.7v1.1+9 more2013-12-20
CVE-2013-7187 [HIGH] CWE-89 CVE-2013-7187: SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allo
SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
nvd