← back
CVE-2021-24144CWE-74

Contact Form 7 Database Addon < 1.2.5.6 - CSV Injection

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.2%
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
nono source reports it
Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.