VsourzCVEs & Vulnerabilities

8 CVEs affecting Vsourz products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

advanced cf7 db 5all in one redirection 2cf7 invisible recaptcha 2
CVE-2024-37245MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vsourz Digital All In One Redirection allows Reflected XSS.This issue affects All In One Redirection: from n/a through 2.2.0.

22 Jul 2024
6.1
CVSS
CVE-2023-28167HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Vsourz Digital CF7 Invisible reCAPTCHA plugin <= 1.3.3 versions.

13 Nov 2023
8.8
CVSS
CVE-2023-2493HIGH

The All In One Redirection WordPress plugin before 2.2.0 does not properly sanitise and escape multiple parameters before using them in an SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

10 Jul 2023
7.2
CVSS
CVE-2022-45285MEDIUM

Vsourz Digital Advanced Contact form 7 DB Versions 1.7.2 and 1.9.1 is vulnerable to Cross Site Scripting (XSS).

13 Feb 2023
6.1
CVSS
CVE-2022-29408MEDIUM

Persistent Cross-Site Scripting (XSS) vulnerability in Vsourz Digital's Advanced Contact form 7 DB plugin <= 1.8.7 at WordPress.

25 May 2022
6.1
CVSS
CVE-2021-24905HIGH

The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server. For example, removing the wp-config.php allows attackers to trigger WordPress setup again, gain administrator privileges and execute arbitrary code or display arbitrary content to the users.

21 Mar 2022
8.0
CVSS
CVE-2018-21012MEDIUM

The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS.

9 Sep 2019
6.1
CVSS
CVE-2019-13571CRITICAL

A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

29 Jul 2019
9.8
CVSS
← PrevPage 1 / 1Next →