| CVE-2025-32692 | WordPress WP Subscription Forms plugin <= 1.2.4 - Local File Inclusion Vulnerability | WP Shuffle | WP Subscription Forms | High | 7.5 | 2025-04-09 16:09:09 | Deep Dive |
| CVE-2025-32279 | WordPress Live Forms plugin <= 4.8.5 - Broken Access Control vulnerability | Shahjada | Live Forms | Medium | 4.3 | 2025-04-08 16:59:35 | Deep Dive |
| CVE-2025-32269 | WordPress WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin <= 1.1.3 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | CRM Perks | WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms | Medium | 4.3 | 2025-04-04 15:59:43 | Deep Dive |
| CVE-2025-32165 | WordPress Doppler Forms plugin <= 2.5.1 - Cross Site Scripting (XSS) vulnerability | fromdoppler | Doppler Forms | Medium | 6.5 | 2025-04-04 15:58:46 | Deep Dive |
| CVE-2025-2836 | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.4.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting | metagauss | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | Medium | 6.4 | 2025-04-04 05:22:45 | Deep Dive |
| CVE-2025-31551 | WordPress Salesmate Add-On for Gravity Forms plugin <= 2.0.3 - SQL Injection vulnerability | Salesmate.io | Salesmate Add-On for Gravity Forms | Critical | 9.3 | 2025-04-01 20:58:12 | Deep Dive |
| CVE-2025-31080 | WordPress HTML Forms plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability | Link Software LLC | HTML Forms | High | 7.1 | 2025-04-01 20:58:09 | Deep Dive |
| CVE-2025-31793 | WordPress Piotnet Forms plugin <= 1.0.30 - Cross Site Scripting (XSS) vulnerability | piotnetdotcom | Piotnet Forms | Medium | 5.9 | 2025-04-01 14:51:31 | Deep Dive |
| CVE-2025-31792 | WordPress Piotnet Forms plugin <= 1.0.30 - Cross Site Scripting (XSS) vulnerability | piotnetdotcom | Piotnet Forms | Medium | 5.9 | 2025-04-01 14:51:31 | Deep Dive |
| CVE-2025-30520 | WordPress Breezing Forms plugin <= 1.2.8.11 - Reflected Cross Site Scripting (XSS) vulnerability | crosstec | Breezing Forms | High | 7.1 | 2025-04-01 05:31:34 | Deep Dive |
| CVE-2025-31615 | WordPress Simple Contact Forms plugin <= 1.6.4 - CSRF to Stored XSS vulnerability | owenr88 | Simple Contact Forms | High | 7.1 | 2025-03-31 12:55:41 | Deep Dive |
| CVE-2025-31533 | WordPress Salesmate Add-On for Gravity Forms plugin <= 2.0.3 - Broken Access Control vulnerability | Salesmate.io | Salesmate Add-On for Gravity Forms | Medium | 5.3 | 2025-03-31 12:55:09 | Deep Dive |
| CVE-2025-31434 | WordPress FormLift for Infusionsoft Web Forms plugin <= 7.5.19 - Cross Site Scripting (XSS) Vulnerability | Adrian Tobey | FormLift for Infusionsoft Web Forms | Medium | 6.5 | 2025-03-28 11:54:21 | Deep Dive |
| CVE-2025-22652 | WordPress Payment Forms for Paystack plugin <= 4.0.1 - SQL Injection vulnerability | kendysond | Payment Forms for Paystack | High | 7.6 | 2025-03-27 15:04:45 | Deep Dive |
| CVE-2025-30863 | WordPress Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin <= 1.0.9 - Cross Site Request Forgery (CSRF) vulnerability | CRM Perks | Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms | Medium | 4.3 | 2025-03-27 10:55:33 | Deep Dive |
| CVE-2025-30809 | WordPress WordPress Contact Form, Drag and Drop Form Builder Plugin – Live Forms plugin <= 4.8.4 - Settings Change vulnerability | Shahjada | Live Forms | Medium | 5.4 | 2025-03-27 10:54:58 | Deep Dive |
| CVE-2025-30784 | WordPress WP Subscription Forms plugin <= 1.2.3 - SQL Injection Vulnerability | WP Shuffle | WP Subscription Forms | High | 8.5 | 2025-03-27 10:54:46 | Deep Dive |
| CVE-2025-30571 | WordPress STEdb Forms plugin <= 1.0.4 - SQL Injection Vulnerability | STEdb Corp. | STEdb Forms | High | 7.6 | 2025-03-24 13:47:06 | Deep Dive |
| CVE-2024-13666 | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Medium | 5.3 | 2025-03-22 08:24:18 | Deep Dive |
| CVE-2025-1530 | Tripetto <= 8.0.9 - Cross-Site Request Forgery to Arbitrary Results Deletion | tripetto | WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto | Medium | 4.3 | 2025-03-15 11:13:29 | Deep Dive |