Known Vulnerabilities for Contact Form by Ghozylab
Listed below are 1 of the newest known vulnerabilities associated with "Contact Form" by "Ghozylab".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-71249 json | 299Ko's public contact form (plugin/contact/controllers/ContactController.php, home()) sets raw POST field values (name, firs... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-66425 json | Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom ... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-65439 json | Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions. | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-65438 json | Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions. | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-57708 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Contact Form ... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-57669 json | Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions. | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-57423 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Fil... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-57411 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman CF7 Views – ... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-57379 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-54893 json | URL path injection in the Microsoft Graph adapter of Swoosh. Swoosh.Adapters.MsGraph builds its Microsoft Graph API request U... | Not Provided | 2026-07-06 | 2026-07-06 |