Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-86832 | 1 Wordpress-extensions | 1 Metform | 2026-10-04 | 5.3 Medium |
| The MetForm WordPress plugin before 4.3.1 does not properly restrict access to form submission data, allowing unauthenticated attackers to view submitter information through the REST API. | ||||
| CVE-2026-86834 | 1 Wordpress-extensions | 1 Metform | 2026-10-04 | 3.7 Low |
| The MetForm WordPress plugin before 4.3.1 does not properly restrict access to a debug file it writes to the web root on every form submission when its HubSpot Forms integration is enabled, allowing unauthenticated attackers to read upstream API response data, including correlation identifiers and cookies. | ||||
| CVE-2026-103339 | 2 Wordpress-extensions, Wpmet | 2 Metform, Metform | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Metform metform allows Stored XSS.This issue affects Metform: from n/a through 4.3.0. | ||||
Page 1 of 1.