Incsub / Forminator
21 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-6464 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Su… | HIGH | 8.8 | Jul 2, 2025 |
| CVE-2025-6463 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submis… | HIGH | 8.8 | Jul 2, 2025 |
| CVE-2024-10402 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation | HIGH | 8.8 | Oct 26, 2024 |
| CVE-2024-45625 | Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on th… | MEDIUM | 6.1 | Sep 9, 2024 |
| CVE-2024-7389 | Forminator <= 1.29.1 - HubSpot Developer API Key Sensitive Information Exposure | HIGH | 7.5 | Aug 2, 2024 |
| CVE-2024-28890 | Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may… | MEDIUM | 5.3 | Apr 23, 2024 |
| CVE-2024-31077 | Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative p… | HIGH | 7.2 | Apr 23, 2024 |
| CVE-2024-31857 | Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain user information etc… | MEDIUM | 5.4 | Apr 23, 2024 |
| CVE-2024-1794 | Forminator <= 1.29.0 - Unauthenticated Stored Cross-Site Scripting via File Upload | HIGH | 7.2 | Apr 9, 2024 |
| CVE-2024-3053 | Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.29.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via forminator_form Shortcode | MEDIUM | 6.4 | Apr 9, 2024 |
| CVE-2024-29777 | WordPress Forminator plugin <= 1.29.0 - Reflected Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | Mar 27, 2024 |
| CVE-2023-5119 | Forminator and Forminator Pro < 1.27.0 - Admin+ Stored Cross-Site Scripting | MEDIUM | 4.8 | Nov 20, 2023 |
| CVE-2023-6133 | Forminator <= 1.27.0 - Authenticated (Administrator+) Arbitrary File Upload | MEDIUM | 6.6 | Nov 15, 2023 |
| CVE-2023-4596 | Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload | CRITICAL | 9.8 | Aug 30, 2023 |
| CVE-2023-3134 | Forminator < 1.24.4 - Reflected XSS | MEDIUM | 6.1 | Jul 31, 2023 |
| CVE-2021-4417 | Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.13.4 - Cross-Site Request Forgery Bypass | MEDIUM | 5.4 | Jul 12, 2023 |
| CVE-2023-2010 | Forminator < 1.24.1 - Unauthenticated Race Condition on poll vote | LOW | 3.1 | Jul 4, 2023 |
| CVE-2021-36821 | WordPress Forminator plugin <= 1.14.11 - Stored Cross-Site Scripting (XSS) vulnerability | HIGH | 7.1 | Mar 16, 2023 |
| CVE-2021-24700 | Forminator < 1.15.4 - Admin+ Stored Cross-Site Scripting | MEDIUM | 4.8 | Nov 23, 2021 |
| CVE-2019-9568 | The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[]… | MEDIUM | 6.5 | Mar 4, 2019 |
| CVE-2019-9567 | The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll. | MEDIUM | 6.1 | Mar 4, 2019 |
Showing 1 to 21 of 21 CVEs