| CVE-2025-3815 | SurveyJS <= 1.12.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter | devsoftbaltic | SurveyJS: Drag & Drop Form Builder | Medium | 6.4 | 2025-05-03 07:22:57 | Deep Dive |
| CVE-2024-13845 | Gravity Forms WebHooks <= 1.6.0 - Authenticated (Admin+) Server-Side Request Forgery via Webhook | Gravity Forms | Gravity Forms WebHooks | Medium | 5.5 | 2025-05-01 04:22:57 | Deep Dive |
| CVE-2025-2801 | Create custom forms for WordPress with a smart form plugin for smart businesses <= 1.2.4 - Unauthenticated Arbitrary Shortcode Execution | dorinabc | Create custom forms for WordPress with a smart form plugin for smart businesses – Form builder for WordPress | High | 7.3 | 2025-04-26 03:24:24 | Deep Dive |
| CVE-2025-46453 | WordPress Zoho Creator Forms <= 1.0.5 - Cross Site Scripting (XSS) Vulnerability | CreatorTeam | Zoho Creator Forms | Medium | 6.5 | 2025-04-24 16:09:07 | Deep Dive |
| CVE-2025-46236 | WordPress HTML Forms plugin <= 1.5.2 - Cross Site Scripting (XSS) Vulnerability | Link Software LLC | HTML Forms | Medium | 6.5 | 2025-04-22 09:53:25 | Deep Dive |
| CVE-2025-32620 | WordPress Doppler Forms plugin <= 2.4.6 - Broken Access Control vulnerability | fromdoppler | Doppler Forms | High | 7.1 | 2025-04-17 15:47:15 | Deep Dive |
| CVE-2025-39428 | WordPress Gravity Forms CSS Themes with Fontawesome and Placeholders plugin <= 8.5 - Cross Site Scripting (XSS) vulnerability | Maros Pristas | Gravity Forms CSS Themes with Fontawesome and Placeholders | Medium | 5.9 | 2025-04-17 15:17:02 | Deep Dive |
| CVE-2025-3487 | Forminator <= 1.42.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'limit' | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Medium | 6.4 | 2025-04-17 11:13:06 | Deep Dive |
| CVE-2025-3479 | Forminator <= 1.42.0 - Order Replay Vulnerability | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Medium | 5.3 | 2025-04-17 11:13:06 | Deep Dive |
| CVE-2025-3615 | Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Medium | 6.4 | 2025-04-17 07:34:08 | Deep Dive |
| CVE-2025-39560 | WordPress Live Forms plugin <= 4.8.4 - Broken Access Control vulnerability | Shahjada | Live Forms | Medium | 5.4 | 2025-04-16 12:44:34 | Deep Dive |
| CVE-2025-39591 | WordPress WP Subscription Forms plugin <= 1.2.3 - Broken Access Control Vulnerability | WP Shuffle | WP Subscription Forms | Medium | 5.4 | 2025-04-16 12:44:20 | Deep Dive |
| CVE-2025-2314 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | cozmoslabs | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | Medium | 6.4 | 2025-04-16 01:45:02 | Deep Dive |
| CVE-2025-3421 | Everest Forms <= 3.1.1 - Reflected Cross-Site Scripting | wpeverest | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | Medium | 6.1 | 2025-04-11 12:42:25 | Deep Dive |
| CVE-2025-3422 | Everest Forms <= 3.1.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution | wpeverest | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | Medium | 5.4 | 2025-04-11 12:42:24 | Deep Dive |
| CVE-2025-3439 | Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 - Unauthenticated PHP Object Injection | wpeverest | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | Critical | 9.8 | 2025-04-11 12:42:24 | Deep Dive |
| CVE-2025-32213 | WordPress Flo Forms plugin <= 1.0.43 - Broken Access Control vulnerability | flothemesplugins | Flo Forms | Medium | 6.5 | 2025-04-10 08:09:45 | Deep Dive |
| CVE-2025-32205 | WordPress Piotnet Forms plugin <= 1.0.30 - Path Traversal vulnerability | piotnetdotcom | Piotnet Forms | - | - | 2025-04-10 08:09:44 | Deep Dive |
| CVE-2024-10894 | Payment Forms for Paystack <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | kendysond | Payment Forms for Paystack | Medium | 6.4 | 2025-04-10 07:02:39 | Deep Dive |
| CVE-2025-32667 | WordPress Doppler Forms plugin <= 2.5.1 - CSRF to Stored XSS vulnerability | fromdoppler | Doppler Forms | High | 7.1 | 2025-04-09 16:09:19 | Deep Dive |