Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rocklobster

First CVE: Mar 14, 2014Active for: 12 yearsTotal CVEs: 10
29.9
VTI Score
Low

Rocklobster's vulnerability footprint centers on WordPress contact-form plugins, a modestly represented but prominent set of widely adopted components that handle user input and file uploads across millions of websites. The exposure skews strongly toward critical-severity outcomes and recurs through web-application weakness classes including unrestricted file uploads, authorization bypass, cross-site request forgery, cross-site scripting, and information disclosure—flaws that are characteristic of plugins with direct access to user submissions and administrative functions. Defenders should treat vulnerabilities in this vendor's contact-form products as high-priority, particularly in internet-facing WordPress installations; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rocklobster over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2014
12 years ago
Most Recent CVE
Apr 16, 2025
465 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-35489CRITICAL
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special character
Dec 17, 202010.079NONO
CVE-2018-20979CRITICAL
The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.
Aug 22, 20199.829NONO
CVE-2023-40609CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aiyaz, maheshpatel Contact form 7 Custom validation allows SQL Injection.This
Nov 6, 20239.827NONO
CVE-2021-24159HIGH
Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact
Apr 5, 20218.825NONO
CVE-2023-6449HIGH
The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function and insufficient blocklisting on
Dec 1, 20237.224NONO
CVE-2024-4704MEDIUM
The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.
Jun 27, 20246.118NONO
CVE-2024-2242MEDIUM
The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 due to insufficient
Mar 13, 20246.118NONO
CVE-2025-3247MEDIUM
The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7_stripe_skip_spam_check' function due to insufficien
Apr 16, 20255.317NONO
CVE-2014-2265MEDIUM
Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_
Mar 14, 20145.017NONO
CVE-2023-6630MEDIUM
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the CF7_get_custo
Jan 11, 20244.315NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
50%
20%
30%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (90.0%)
Unknown1 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High0 (0.0%)
Unknown1 (10.0%)
User Interaction
None6 (60.0%)
Unknown1 (10.0%)
Required3 (30.0%)
Privileges Required
Low1 (10.0%)
High1 (10.0%)
None7 (70.0%)
Unknown1 (10.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rocklobster.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rocklobster — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rocklobster's Products

View all 4 CNAs →

Top CWEs