Contact Forms is a niche form-builder plugin whose vulnerability profile centers on a single product, cforms, exposed to user-supplied content and configuration. The durable signal reflects code-injection risks inherent to form-processing and dynamic handler construction, a structural exposure in applications that render user input into executable contexts. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Contact Forms over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0560MEDIUM PHP remote file inclusion vulnerability in cforms-css.php in Oliver Seidel cforms (contactforms), a Wordpress plugin, allows remote attackers to execute arbitrary PHP code via a UR | Feb 4, 2008 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Contact Forms.
Media articles that mention a CVE ID that affects a product developed by Contact Forms — matched by CVE ID, not by vendor name.