Skip to main content

Vendor/product archive

codepeople / calculated_fields_form CVEs

Beta · best-effort

13 CVEs tagged to codepeople / calculated_fields_form0 Critical, 2 High, 10 Medium, 1 Low, 0 Unrated.

CVE-2025-49291

Published Jun 6, 2025

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Cross Site Request Forgery.This issue affects Calculated Fields…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13382

Published May 15, 2025

The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13381

Published May 1, 2025

The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12273

Published Apr 29, 2025

The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-12601

Published Dec 17, 2024

The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to unlimited height and width paramete…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9940

Published Oct 17, 2024

The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing H…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26523

Published Jun 3, 2024

Missing Authorization vulnerability in CodePeople Calculated Fields Form allows Functionality Misuse.This issue affects Calculated Fields Form: from n/a through 1.1.120.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-29759

Published Mar 27, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Calculated Fields Form allows Reflected XSS.This issue affects Cal…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2020

Published Mar 13, 2024

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form page href parameter in all versions up to, and including, 5.1.56 due to i…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0963

Published Feb 2, 2024

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's CP_CALCULATED_FIELDS shortcode in all versions up to, and including,…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-0389

Published Jan 16, 2024

The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-51517

Published Dec 29, 2023

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: from n/a through 1.2.28.

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-7228

Published Jan 22, 2020

The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authentic…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1