DeliciousdaysCVEs & Vulnerabilities
2 CVEs affecting Deliciousdays products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
cforms 1cformsii 1
CVE-2014-9473HIGHpoc
Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file via a direct request to the file in the default upload directory.
8 Jan 2015
7.5
CVSS
CVE-2010-3977MEDIUMpoc
Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
3 Nov 2010
4.3
CVSS
← PrevPage 1 / 1Next →