strategy11 CVE Vulnerabilities & Metrics

Focus on strategy11 vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About strategy11 Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with strategy11. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total strategy11 CVEs: 26
Earliest CVE date: 13 Jan 2015, 11:59 UTC
Latest CVE date: 13 Dec 2024, 15:15 UTC

Latest CVE reference: CVE-2022-45806

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 6

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -14.29%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -14.29%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical strategy11 CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.38

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 17
4.0-6.9 7
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS strategy11 CVEs

These are the five CVEs with the highest CVSS scores for strategy11, sorted by severity first and recency.

All CVEs for strategy11

CVE-2022-45806 strategy11 vulnerability CVSS: 0 13 Dec 2024, 15:15 UTC

Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Formidable Forms: from n/a through 5.5.4.

CVE-2024-9768 strategy11 vulnerability CVSS: 0 21 Nov 2024, 11:15 UTC

The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2017-20194 strategy11 vulnerability CVSS: 0 16 Oct 2024, 08:15 UTC

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.

CVE-2024-6725 strategy11 vulnerability CVSS: 0 31 Jul 2024, 11:15 UTC

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ parameter in all versions up to, and including, 6.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with form editing permissions and Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-31350 strategy11 vulnerability CVSS: 0 09 Jun 2024, 18:15 UTC

Missing Authorization vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1.

CVE-2024-23522 strategy11 vulnerability CVSS: 0 17 May 2024, 09:15 UTC

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affects Formidable Forms: from n/a through 6.7.

CVE-2024-0660 strategy11 vulnerability CVSS: 0 05 Feb 2024, 22:16 UTC

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.2. This is due to missing or incorrect nonce validation on the update_settings function. This makes it possible for unauthenticated attackers to change form settings and add malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-1405 strategy11 vulnerability CVSS: 0 16 Jan 2024, 16:15 UTC

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.

CVE-2023-6842 strategy11 vulnerability CVSS: 0 09 Jan 2024, 07:15 UTC

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name field label and description field label parameter in all versions up to 6.7 (inclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this only affects multi-site installations and installations where unfiltered_html has been disabled. However, in the formidable settings admins can extend form creation, deletion and other management permissions to other user types, which makes it possible for this vulnerability to be exploited by lower level user types as long as they have been granted the proper permissions.

CVE-2023-6830 strategy11 vulnerability CVSS: 0 09 Jan 2024, 07:15 UTC

The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrary HTML code into form fields. When the form data is viewed by an administrator in the Entries View Page, the injected HTML code is rendered, potentially leading to admin area defacement or redirection to malicious websites.

CVE-2023-41801 strategy11 vulnerability CVSS: 0 06 Oct 2023, 15:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions.

CVE-2023-2877 strategy11 vulnerability CVSS: 0 27 Jun 2023, 14:15 UTC

The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.

CVE-2023-0816 strategy11 vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.

CVE-2023-24419 strategy11 vulnerability CVSS: 0 28 Feb 2023, 14:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Form Builder Team Formidable Forms plugin <= 5.5.6 versions.

CVE-2022-3254 strategy11 vulnerability CVSS: 0 31 Oct 2022, 16:15 UTC

The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection

CVE-2021-24884 strategy11 vulnerability CVSS: 6.8 25 Oct 2021, 14:15 UTC

The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link. If the Link gets clicked, Javascript code can be executed. The vulnerability is due to insufficient sanitization of the "data-frmverify" tag for links in the web-based entry inspection page of affected systems. A successful exploitation incomibantion with CSRF could allow the attacker to perform arbitrary actions on an affected system with the privileges of the user. These actions include stealing the users account by changing their password or allowing attackers to submit their own code through an authenticated user resulting in Remote Code Execution. If an authenticated user who is able to edit Wordpress PHP Code in any kind, clicks the malicious link, PHP code can be edited.

CVE-2021-24608 strategy11 vulnerability CVSS: 3.5 25 Oct 2021, 14:15 UTC

The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-24251 strategy11 vulnerability CVSS: 4.3 06 May 2021, 13:15 UTC

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from pending to completed to example)

CVE-2021-24250 strategy11 vulnerability CVSS: 3.5 06 May 2021, 13:15 UTC

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of the plugin.

CVE-2021-24249 strategy11 vulnerability CVSS: 4.3 06 May 2021, 13:15 UTC

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator export files, which could then be downloaded by the attacker to get access to PII, such as email, home addresses etc

CVE-2021-24248 strategy11 vulnerability CVSS: 6.5 06 May 2021, 13:15 UTC

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example, leading to RCE

CVE-2021-24179 strategy11 vulnerability CVSS: 6.8 06 May 2021, 13:15 UTC

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate uploaded files, it could lead to RCE.

CVE-2021-24178 strategy11 vulnerability CVSS: 6.8 06 May 2021, 13:15 UTC

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.

CVE-2019-15780 strategy11 vulnerability CVSS: 7.5 29 Aug 2019, 12:15 UTC

The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.

CVE-2014-10013 strategy11 vulnerability CVSS: 7.5 13 Jan 2015, 11:59 UTC

SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.

CVE-2014-10012 strategy11 vulnerability CVSS: 4.3 13 Jan 2015, 11:59 UTC

Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.