Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-52140 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder allows SQL Injection.This issue affects NEX-Forms – Ultimate Form Builder: from n/a through 8.7.8. | 
Solution
Update the WordPress NEX-Forms – Ultimate Form Builder plugin to the latest available version (at least 8.7.9).
Workaround
No workaround given by the vendor.
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Wed, 22 Jan 2025 18:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Basixonline
         Basixonline nex-forms  | 
|
| CPEs | cpe:2.3:a:basixonline:nex-forms:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products | 
        
        Basixonline
         Basixonline nex-forms  | 
Fri, 06 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Fri, 06 Dec 2024 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder allows SQL Injection.This issue affects NEX-Forms – Ultimate Form Builder: from n/a through 8.7.8. | |
| Title | WordPress NEX-Forms plugin <= 8.7.8 - SQL Injection vulnerability | |
| Weaknesses | CWE-89 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2024-12-06T18:15:55.886Z
Reserved: 2024-11-22T13:53:36.471Z
Link: CVE-2024-53808
Updated: 2024-12-06T18:15:52.216Z
Status : Analyzed
Published: 2024-12-06T14:15:23.233
Modified: 2025-01-22T18:04:55.013
Link: CVE-2024-53808
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD