Skip to main content

Vendor archive

verbb CVEs

Beta · best-effort

10 CVEs tagged to vendor verbb1 Critical, 1 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2025-32427

Published Apr 11, 2025

Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, if the field label or handle contained malicious content, the output wasn't corr…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-32426

Published Apr 11, 2025

Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email notification, which is then ren…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-35191

Published May 20, 2024

Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13870

Published Jun 5, 2020

An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13869

Published Jun 5, 2020

An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13868

Published Jun 5, 2020

An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13485

Published May 25, 2020

The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-13459

Published May 25, 2020

An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13458

Published May 25, 2020

An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1