Lucene search

K

Captcha Security Vulnerabilities

cve
cve

CVE-2023-48745

Improper Restriction of Excessive Authentication Attempts vulnerability in WebFactory Ltd Captcha Code allows Functionality Bypass.This issue affects Captcha Code: from n/a through...

5.3CVSS

7.3AI Score

0.0004EPSS

2024-06-04 11:15 AM
42
cve
cve

CVE-2023-48276

Improper Restriction of Excessive Authentication Attempts vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Functionality Bypass.This issue affects WP Forms Puzzle Captcha: from n/a through...

5.3CVSS

7.2AI Score

0.0004EPSS

2024-06-04 11:15 AM
37
cve
cve

CVE-2023-45009

Improper Restriction of Excessive Authentication Attempts vulnerability in Forge12 Interactive GmbH Captcha/Honeypot for Contact Form 7 allows Functionality Bypass.This issue affects Captcha/Honeypot for Contact Form 7: from n/a through...

5.3CVSS

7.2AI Score

0.0004EPSS

2024-06-04 09:15 AM
1
cve
cve

CVE-2023-44235

Improper Restriction of Excessive Authentication Attempts vulnerability in Devnath verma WP Captcha allows Functionality Bypass.This issue affects WP Captcha: from n/a through...

5.3CVSS

7.2AI Score

0.0004EPSS

2024-06-04 08:15 AM
13
cve
cve

CVE-2023-40673

: Improper Control of Interaction Frequency vulnerability in cartpauj Cartpauj Register Captcha allows Functionality Misuse.This issue affects Cartpauj Register Captcha: from n/a through...

6.5CVSS

7.2AI Score

0.0004EPSS

2024-06-04 08:15 AM
2
cve
cve

CVE-2024-31295

Guessable CAPTCHA vulnerability in BestWebSoft Captcha by BestWebSoft allows Functionality Bypass.This issue affects Captcha by BestWebSoft: from n/a through...

5.3CVSS

6.8AI Score

0.0004EPSS

2024-05-17 09:15 AM
27
cve
cve

CVE-2023-45771

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contact Form With Captcha allows Reflected XSS.This issue affects Contact Form With Captcha: from n/a through...

7.1CVSS

6.8AI Score

0.0004EPSS

2024-03-26 09:15 AM
64
cve
cve

CVE-2023-48278

Cross-Site Request Forgery (CSRF) vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Stored XSS.This issue affects WP Forms Puzzle Captcha: from n/a through...

7.1CVSS

6.4AI Score

0.0005EPSS

2023-11-30 05:15 PM
45
cve
cve

CVE-2023-46777

Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha plugin <= 1.1.3...

8.8CVSS

8.8AI Score

0.001EPSS

2023-11-06 12:15 PM
25
cve
cve

CVE-2023-46210

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebCource WC Captcha plugin <= 1.4...

5.9CVSS

4.9AI Score

0.0004EPSS

2023-10-31 08:15 AM
16
cve
cve

CVE-2023-44997

Cross-Site Request Forgery (CSRF) vulnerability in Nitin Rathod WP Forms Puzzle Captcha plugin <= 4.1...

8.8CVSS

8.8AI Score

0.001EPSS

2023-10-11 08:15 AM
28
cve
cve

CVE-2023-44236

Cross-Site Request Forgery (CSRF) vulnerability in Devnath verma WP Captcha plugin <= 2.0.0...

8.8CVSS

8.8AI Score

0.001EPSS

2023-10-09 10:15 AM
23
cve
cve

CVE-2023-5135

The Simple Cloudflare Turnstile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gravity-simple-turnstile' shortcode in versions up to, and including, 1.23.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...

6.4CVSS

5.2AI Score

0.001EPSS

2023-09-27 03:19 PM
33
cve
cve

CVE-2023-30786

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Benjamin Guy Captcha Them All plugin <= 1.3.3...

5.9CVSS

4.8AI Score

0.0004EPSS

2023-08-16 10:15 AM
9
cve
cve

CVE-2023-33312

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wppal Easy Captcha plugin <= 1.0...

7.1CVSS

5.9AI Score

0.001EPSS

2023-07-18 06:15 PM
12
cve
cve

CVE-2023-2549

The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions starting from 1.0.7 up to, and including, 1.1.1. This is due to missing nonce validation in the 'createTempAccountLink' function. This makes it possible for unauthenticated attackers to create a new....

8.8CVSS

8.3AI Score

0.001EPSS

2023-05-31 03:15 AM
20
cve
cve

CVE-2023-2547

The Feather Login Page plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'deleteUser' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with subscriber-level permissions...

5.4CVSS

5.4AI Score

0.001EPSS

2023-05-31 03:15 AM
18
cve
cve

CVE-2023-2545

The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getListOfUsers' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with subscriber-level...

8.8CVSS

8.2AI Score

0.001EPSS

2023-05-31 03:15 AM
19
cve
cve

CVE-2023-0147

The Flexible Captcha WordPress plugin through 4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting...

5.4CVSS

5.3AI Score

0.001EPSS

2023-02-06 08:15 PM
25
cve
cve

CVE-2009-10001

A vulnerability classified as problematic was found in jianlinwei cool-php-captcha up to 0.2. This vulnerability affects unknown code of the file example-form.php. The manipulation of the argument captcha with the input %3Cscript%3Ealert(1)%3C/script%3E leads to cross site scripting. The attack...

6.1CVSS

6.1AI Score

0.001EPSS

2023-01-13 06:15 PM
20
cve
cve

CVE-2005-4163

Directory traversal vulnerability in captcha.php in Captcha PHP 0.9 allows remote attackers to read arbitrary files via the _tcf...

7.2AI Score

0.003EPSS

2022-10-03 04:22 PM
18
cve
cve

CVE-2022-2913

The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login...

4.3CVSS

4.6AI Score

0.001EPSS

2022-09-16 09:15 AM
30
7
cve
cve

CVE-2022-37411

Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza's Captcha Code plugin <= 2.7 at...

8.8CVSS

8.9AI Score

0.001EPSS

2022-09-09 03:15 PM
24
3
cve
cve

CVE-2022-2184

The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abused by attackers, via a Cross-Site Request Forgery attack to run arbitrary code on the...

8.8CVSS

8.7AI Score

0.001EPSS

2022-08-01 01:15 PM
36
4
cve
cve

CVE-2022-34983

The scu-captcha package in PyPI v0.0.1 to v0.0.4 included a code execution backdoor inserted by a third...

9.8CVSS

9.6AI Score

0.003EPSS

2022-07-22 03:15 PM
32
2
cve
cve

CVE-2022-2187

The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web...

6.1CVSS

6AI Score

0.001EPSS

2022-07-17 11:15 AM
42
2
cve
cve

CVE-2022-24880

flask-session-captcha is a package which allows users to extend Flask by adding an image based captcha stored in a server side session. In versions prior to 1.2.1, he captcha.validate() function would return None if passed no value (e.g. by submitting an having an empty form). If implementing...

5.3CVSS

5AI Score

0.001EPSS

2022-04-25 10:15 PM
79
cve
cve

CVE-2021-42358

The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php file during contact form submission, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including...

8.8CVSS

8.6AI Score

0.001EPSS

2021-11-29 07:15 PM
14
cve
cve

CVE-2021-24565

The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored...

8.8CVSS

7.7AI Score

0.001EPSS

2021-08-23 12:15 PM
33
4
cve
cve

CVE-2020-15514

The jh_captcha extension through 2.1.3, and 3.x through 3.0.2, for TYPO3 allows...

5.4CVSS

5.5AI Score

0.001EPSS

2020-07-07 02:15 PM
20
cve
cve

CVE-2015-6250

simple-php-captcha before commit 9d65a945029c7be7bb6bc893759e74c5636be694 allows remote attackers to automatically generate the captcha response by running the same code on the...

5.3CVSS

5.5AI Score

0.003EPSS

2017-09-06 09:29 PM
16
cve
cve

CVE-2017-2171

Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior...

6.1CVSS

6.1AI Score

0.001EPSS

2017-05-22 04:29 PM
33
cve
cve

CVE-2015-0890

The BestWebSoft Google Captcha (aka reCAPTCHA) plugin before 1.13 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified...

6.9AI Score

0.003EPSS

2015-03-03 11:59 AM
24
cve
cve

CVE-2014-9283

The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified...

7AI Score

0.003EPSS

2015-03-03 11:59 AM
22
cve
cve

CVE-2014-5190

Cross-site scripting (XSS) vulnerability in captcha-secureimage/test/index.php in the SI CAPTCHA Anti-Spam plugin 2.7.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the...

5.9AI Score

0.003EPSS

2014-08-07 11:13 AM
19
cve
cve

CVE-2013-4680

Open redirect vulnerability in Maag Form Captcha extension 2.0.0 and earlier for TYPO3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified...

6.9AI Score

0.003EPSS

2013-06-25 06:55 PM
21
cve
cve

CVE-2012-2914

Cross-site scripting (XSS) vulnerability in captchademo.php in Unijimpe Captcha allows remote attackers to inject arbitrary web script or HTML via the...

5.9AI Score

0.002EPSS

2012-05-21 06:55 PM
22
cve
cve

CVE-2008-5995

Cross-site scripting (XSS) vulnerability in the freeCap CAPTCHA (sr_freecap) extension before 1.0.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified...

5.9AI Score

0.003EPSS

2009-01-28 03:30 PM
22
cve
cve

CVE-2008-0206

Multiple cross-site scripting (XSS) vulnerabilities in captcha\captcha.php in the Captcha! 2.5d and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) captcha_ttffolder, (2) captcha_numchars, (3) captcha_ttfrange, or (4) captcha_secret...

5.9AI Score

0.002EPSS

2008-01-10 12:46 AM
20
cve
cve

CVE-2006-2918

The Lanap BotDetect APS.NET CAPTCHA component before 1.5.4.0 stores the UUID and hash for a CAPTCHA in the ViewState of a page, which makes it easier for remote attackers to conduct automated attacks by "replaying the ViewState for a known...

6.6AI Score

0.034EPSS

2006-06-23 09:06 PM
24