Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-86833 | 1 Wordpress-extensions | 1 Metform | 2026-10-09 | 5.4 Medium |
| The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends. | ||||
| CVE-2026-86832 | 1 Wordpress-extensions | 1 Metform | 2026-10-04 | 5.3 Medium |
| The MetForm WordPress plugin before 4.3.1 does not properly restrict access to form submission data, allowing unauthenticated attackers to view submitter information through the REST API. | ||||
| CVE-2026-86834 | 1 Wordpress-extensions | 1 Metform | 2026-10-04 | 3.7 Low |
| The MetForm WordPress plugin before 4.3.1 does not properly restrict access to a debug file it writes to the web root on every form submission when its HubSpot Forms integration is enabled, allowing unauthenticated attackers to read upstream API response data, including correlation identifiers and cookies. | ||||
| CVE-2026-103339 | 2 Wordpress-extensions, Wpmet | 2 Metform, Metform | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Metform metform allows Stored XSS.This issue affects Metform: from n/a through 4.3.0. | ||||
Page 1 of 1.