Home/Product/oracle forms
Product

oracle forms

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-45543
>= 4.3.0 and < 5.2.7
Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator ret
5.3MEDIUM
CVE-2021-37334
>= 4.0.0 and < 4.4.9
Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that could lead to a remote code
9.8CRITICAL
CVE-2021-24505
< 1.12.3
The Forms WordPress plugin before 1.12.3 did not sanitise its input fields, leading to Stored Cross-Site scripting issues. The plu
5.4MEDIUM
CVE-2021-23388
< 1.2.1
The package forms before 1.2.1, from 1.3.0 and before 1.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via ema
5.3MEDIUM
CVE-2019-2886
all versions
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Services). The supported version that is affecte
6.1MEDIUM
CVE-2017-16015
< 1.3.0
Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means that if the
6.1MEDIUM
CVE-2010-3260
<= 3.8.1
oxf/xml/xerces/XercesSAXParserFactoryImpl.java in the xforms-server component in the XForms service in Orbeon Forms before 3.9 doe
CVE-2005-3207
all versions
The forms servlet (f90servlet) in Oracle Forms 4.5.10.22 allows remote attackers to cause a denial of service (TNS listener stop)
CVE-2005-2372
all versions
Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, wh
CVE-2005-2294
all versions
Oracle Forms 4.5, 6.0, 6i, and 9i on Unix, when a large number of records are retrieved by an Oracle form, stores a copy of the da
CVE-2005-1178
all versions
SQL injection vulnerability in Oracle Forms 10g allows remote attackers to execute arbitrary SQL commands via the Query/Where feat
threatengine.sh