Contact Form Submissions Project maintains a web form handling component whose vulnerability profile centers on application-layer input-handling weaknesses, specifically cross-site scripting and SQL injection flaws arising from insufficient neutralization of user-supplied data. This narrow product scope reflects a focused utility with durable exposure to web input validation challenges; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Contact Form Submissions Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0248MEDIUM The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. | Mar 14, 2022 | 6.1 | 23 | NO | NO |
CVE-2021-24125HIGH Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf7_contact_form GET parameter when submitting a filter reques | Mar 18, 2021 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Contact Form Submissions Project.
Media articles that mention a CVE ID that affects a product developed by Contact Form Submissions Project — matched by CVE ID, not by vendor name.