Skip to main content

Vendor/product archive

incsub / forminator CVEs

Beta · best-effort

20 CVEs tagged to incsub / forminator1 Critical, 7 High, 11 Medium, 1 Low, 0 Unrated.

CVE-2025-6464

Published Jul 2, 2025

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6463

Published Jul 2, 2025

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t…

CVSS 8.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-45625

Published Sep 9, 2024

Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7389

Published Aug 2, 2024

The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. Thi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31857

Published Apr 23, 2024

Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain user information etc. and alter the page…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-31077

Published Apr 23, 2024

Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-28890

Published Apr 23, 2024

Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive in…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-3053

Published Apr 9, 2024

The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ forminator_form shortcode attribut…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1794

Published Apr 9, 2024

The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) in all versions up to, and including, 1.29.0 due to insuffic…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29777

Published Mar 27, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator.This issu…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5119

Published Nov 20, 2023

The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission settings, which could allow high-privilege users such as an…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6133

Published Nov 15, 2023

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'forminator_allowed_mime_types' function in versions up to, and…

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-4596

Published Aug 30, 2023

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_i…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-3134

Published Jul 31, 2023

The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form fields that use pre-populated query parameters, which could lead…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-4417

Published Jul 12, 2023

The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.13.4. This i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2010

Published Jul 4, 2023

The Forminator WordPress plugin before 1.24.1 does not use an atomic operation to check whether a user has already voted, and then update that information. This leads to a Race Co…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-36821

Published Mar 16, 2023

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Stored XSS.This issue affects Forminator: f…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24700

Published Nov 23, 2021

The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks ev…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9568

Published Mar 4, 2019

The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the at…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9567

Published Mar 4, 2019

The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1