| CVE-2024-40744 | Extension - tassos.gr - Unrestricted file upload in Convert Forms component for Joomla < 4.4.8 | tassos.gr | Convert Forms component for Joomla | 中危 | - | 2024-12-04 15:01:51 | Deep Dive |
| CVE-2024-11326 | Campaign Monitor Forms by Optin Cat <= 2.5.7 - Reflected Cross-Site Scripting | fatcatapps | Campaign Monitor Forms by Optin Cat | Medium | 6.1 | 2024-12-03 11:04:04 | Deep Dive |
| CVE-2024-11325 | AWeber Forms by Optin Cat <= 2.5.7 - Reflected Cross-Site Scripting | fatcatapps | AWeber Forms by Optin Cat | Medium | 5.2 | 2024-12-03 09:32:00 | Deep Dive |
| CVE-2024-53784 | WordPress Smart Marketing SMS and Newsletters Forms plugin <= 5.0.4 - Broken Access Control vulnerability | E-goi | Smart Marketing SMS and Newsletters Forms | Medium | 4.3 | 2024-12-02 13:48:27 | Deep Dive |
| CVE-2024-10521 | WordPress Contact Forms by Cimatti <= 1.9.2 - Cross-Site Request Forgery via process_bulk_action Function | cimatti | Contact Forms by Cimatti | Medium | 4.3 | 2024-11-27 11:03:34 | Deep Dive |
| CVE-2024-10471 | Everest Forms < 3.0.4.2 - Admin+ Stored XSS | Unknown | Everest Forms | - | - | 2024-11-26 06:00:07 | Deep Dive |
| CVE-2024-11188 | Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.16.1.2 - Reflected Cross-Site Scripting via Custom HTML Form Parameter | strategy11team | Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder | Medium | 6.1 | 2024-11-23 05:40:11 | Deep Dive |
| CVE-2024-11332 | HIPAA Compliant Forms with Drag’n’Drop HIPAA Form Builder. Sign HIPAA documents <= 1.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | hipaatizer | HIPAA Compliant Forms with Drag’n’Drop HIPAA Form Builder. Sign HIPAA documents | Medium | 6.4 | 2024-11-23 04:32:21 | Deep Dive |
| CVE-2024-9768 | Formidable Forms < 6.14.1 - Admin+ Stored XSS | Unknown | Formidable Forms | 中危 | - | 2024-11-21 06:00:10 | Deep Dive |
| CVE-2024-8726 | MailChimp Forms by MailMunch <= 3.2.3 - Reflected Cross-Site Scripting | mailmunch | MailChimp Forms by MailMunch | Medium | 6.1 | 2024-11-20 06:42:55 | Deep Dive |
| CVE-2024-50515 | WordPress Ninja Forms – The Contact Form Builder That Grows With You plugin <= 3.8.16 - Cross Site Scripting (XSS) vulnerability | Kevin Stover | Ninja Forms | Medium | 5.9 | 2024-11-19 16:32:17 | Deep Dive |
| CVE-2024-50514 | WordPress Ninja Forms – The Contact Form Builder That Grows With You plugin <= 3.8.16 - Cross Site Scripting (XSS) vulnerability | Kevin Stover | Ninja Forms | Medium | 5.9 | 2024-11-19 16:32:17 | Deep Dive |
| CVE-2024-51877 | WordPress SV Forms plugin <= 2.0.05 - Cross Site Scripting (XSS) vulnerability | straightvisions GmbH | SV Forms | Medium | 6.5 | 2024-11-19 16:31:20 | Deep Dive |
| CVE-2024-52339 | WordPress Mage Front End Forms plugin <= 1.1.4 - Cross Site Scripting (XSS) vulnerability | Maximilian Ruthe | Mage Front End Forms | Medium | 6.5 | 2024-11-18 22:15:57 | Deep Dive |
| CVE-2024-10260 | Tripetto <= 8.0.11 - Unauthentiated Stored Cross-Site Scripting via Form File Upload | tripetto | WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto | High | 7.2 | 2024-11-15 05:30:56 | Deep Dive |
| CVE-2024-10593 | WPForms – Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion | smub | WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More | Medium | 4.3 | 2024-11-13 02:33:17 | Deep Dive |
| CVE-2024-10717 | Styler for Ninja Forms <= 3.3.4 - Authenticated (Subscriber+) Arbitrary Option Deletion via deactivate_license | wpmonks | Styler for Ninja Forms | Medium | 6.5 | 2024-11-13 02:02:34 | Deep Dive |
| CVE-2024-9614 | Constant Contact Forms by MailMunch <= 2.1.2 - Reflected Cross-Site Scripting | mailmunch | Constant Contact Forms by MailMunch | Medium | 6.1 | 2024-11-13 02:02:33 | Deep Dive |
| CVE-2024-51791 | WordPress Forms plugin <= 2.8.0 - Arbitrary File Upload vulnerability | Made I.T. | Forms | Critical | 10.0 | 2024-11-11 05:54:39 | Deep Dive |
| CVE-2024-51783 | WordPress Forms: 3rd-Party Post Again plugin <= 0.3 - Reflected Cross Site Scripting (XSS) vulnerability | zaus | Forms: 3rd-Party Post Again | High | 7.1 | 2024-11-09 08:29:59 | Deep Dive |