Skip to main content

Vendor archive

cartflows CVEs

Beta · best-effort

5 CVEs tagged to vendor cartflows0 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2023-36686

Published Aug 5, 2023

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CartFlows Pro plugin <= 1.11.11 versions.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-36736

Published Jul 1, 2023

The WooCommerce Checkout & Funnel Builder by CartFlows plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.15. This is due to mi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-25151

Published Jun 7, 2023

The Funnel Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the activate_plugin function in versions up to, and including, 1…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24330

Published Jun 1, 2021

The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings,…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1