Known vulnerabilities in Caldera Forms - More Than Contact Forms
Vendor:
Caldera Labs
Software:
Caldera Forms - More Than Contact Forms
Software CPE:
cpe:2.3:a:shelob9:caldera-forms:*:*:*:*:*:wordpress:*:*
Total vulnerabilities:
3
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
1.9.4
1.9.3
1.9.2
1.9.1
1.9.0
1.8.11
1.8.10
1.8.9
1.8.8
1.8.7
1.8.6
1.8.5
1.6.3
1.6.2-rc.1
1.6.2
1.6.1.rc.1
1.6.1.beta.1
1.6.1.1
1.6.1
1.6.0
1.5.9.1
1.5.9-rc.1
1.5.9
1.5.8.2
1.5.8.1
1.5.8
1.5.7.1
1.5.7
1.5.6.2
1.5.6.1
1.5.6
1.5.5
1.5.4
1.5.3.1
1.5.3
1.5.2.1
1.5.2
1.5.1
1.5.0.9
1.5.0.8
1.5.0.7
1.5.0.6
1.5.0.5
1.5.0.4
1.5.0.3
1.5.0.2
1.5.0.10
1.5.0.1
1.5.0
1.4.9.1
1.4.0
1.3.5.3
1.3.0
1.2.2
1.2.1
1.2.0
1.1.9.10
1.1.0
1.0.91
1.0.0
1.8.4
1.8.3
1.8.2
1.8.1
1.8.0
1.7.7
1.7.6
1.7.5.1
1.7.4
1.7.3
1.7.2
1.7.1.4
1.7.1.3
1.7.1.2
1.7.1.1
1.7.1
1.7.0-b.1
1.7.0
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU20601 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
CWE-79 | Low | 1.5.5 | 02.09.2019 |
SB2017090816 |
||
| #VU19661 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2018-7747 |
CWE-79 | Low | 1.6.0 | 02.08.2019 |
SB2018042613 |
||
| #VU18080 - Improper Access Control |
CWE-284 | High | 1.7.7, 1.8.2 | 25.03.2019 |
SB2019031401 SB2019031402 |