Skip to content

Known CVE

Formcraft3 <3.8.28 - Server-Side Request Forgery

Formcraft3 before version 3.8.2 does not validate the URL parameter in the formcraft3_get AJAX action, leading to server-side request forgery issues exploitable by unauthenticated users.

CVE-2022-0591

Critical2022CVSS 9.1CWE-918

cve2022 · wp · wp-plugin · wordpress · formcraft3 · wpscan · ssrf · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website