
CVE-2016-1000139 – Infusionsoft Gravity Forms Add-on <= 1.5.11 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2016-1000139
02 Sep 2016 — Reflected XSS in wordpress plugin infusionsoft v1.5.11 Vulnerabilidad de XSS reflejada en el plugin de wordpress infusionsoft v1.5.11 Reflected XSS in wordpress plugin infusionsoft v1.5.11 via the 'ContactId' parameter. • http://www.securityfocus.com/bid/93819 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-6446 – Infusionsoft Gravity Forms Add-on 1.5.3 - 1.5.10 - Arbitrary File Upload
https://notcve.org/view.php?id=CVE-2014-6446
26 Sep 2014 — The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php. El plugin Infusionsoft Gravity Forms 1.5.3 hasta 1.5.10 para WordPress no restringe debidamente el acceso, lo que permite a atacantes remotos subir ficheros arbitrarios y ejecutar código PHP arbitrario a través de una solicitud en utilities/code_generator.php. • https://packetstorm.news/files/id/128591 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-434: Unrestricted Upload of File with Dangerous Type •