Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
15024.1%MEDIUM

Related CVEs

5
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2024-10054The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).MEDIUM4.817.9%May 15, 2025
CVE-2024-44063Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Happyforms allows Stored XSS.This issue affects Happyforms: from n/a through 1.26.0.MEDIUM5.415.7%Sep 15, 2024
CVE-2024-23521Missing Authorization vulnerability in Happyforms.This issue affects Happyforms: from n/a through 1.25.10.MEDIUM5.330.0%Jun 11, 2024
CVE-2023-48752Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Happyforms Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms allows Reflected XSS.This issue affects Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms: from n/a through 1.25.9.MEDIUM6.132.9%Nov 30, 2023
CVE-2023-0096The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.MEDIUM5.4Feb 6, 2023