| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-48341 | WordPress Form Maker by 10Web plugin <= 1.15.33 - Cross Site Scripting (XSS) Vulnerability | 10Web | Form Maker by 10Web | Medium | 5.9 | 2025-05-19 14:55:22 | Deep Dive |
| CVE-2025-31915 | WordPress Pixel Form BuilderPlugin & Autoresponder plugin <= 1.0.3 - Cross Site Request Forgery (CSRF) vulnerability | kamleshyadav | Pixel WordPress Form BuilderPlugin & Autoresponder | Medium | 5.4 | 2025-05-16 15:45:37 | Deep Dive |
| CVE-2025-3201 | Kali Forms < 2.4.3 - Contributor+ Stored XSS | Unknown | Contact Form builder with drag & drop for WordPress | - | - | 2025-05-16 06:00:04 | Deep Dive |
| CVE-2024-13382 | Calculated Fields Form < 5.2.64 - Admin+ Stored XSS | Unknown | Calculated Fields Form | - | - | 2025-05-15 20:07:01 | Deep Dive |
| CVE-2024-13053 | Form Maker by 10Web < 1.15.33 - Admin+ Stored XSS via Theme Title | Unknown | Form Maker by 10Web | - | - | 2025-05-15 20:06:58 | Deep Dive |
| CVE-2024-12750 | Competition Form <= 2.0 - Competition Deletion via CSRF | Unknown | Competition Form | - | - | 2025-05-15 20:06:56 | Deep Dive |
| CVE-2024-12716 | Simple Basic Contact Form < 20250114 - Admin+ Stored XSS | Unknown | Simple Basic Contact Form | - | - | 2025-05-15 20:06:54 | Deep Dive |
| CVE-2024-10504 | ARForms Builder < 1.7.1 - Unauthenticated Stored XSS | Unknown | Contact Form, Survey, Quiz & Popup Form Builder | - | - | 2025-05-15 20:06:44 | Deep Dive |
| CVE-2024-10475 | Lead Form Builder < 1.9.8 - Admin+ Stored XSS | Unknown | Responsive Contact Form Builder & Lead Generation Plugin | - | - | 2025-05-15 20:06:43 | Deep Dive |
| CVE-2025-3794 | WPForms Lite <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parameter | smub | WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More | Medium | 5.4 | 2025-05-09 22:22:13 | Deep Dive |
| CVE-2025-47644 | WordPress Integrations of Zoho CRM with Elementor form plugin <= 1.0.8 - Open Redirection Vulnerability | formsintegrations | Integrations of Zoho CRM with Elementor form | Medium | 4.7 | 2025-05-07 14:20:43 | Deep Dive |
| CVE-2025-47626 | WordPress Submission DOM tracking for Contact Form 7 plugin <= 2.1 - Cross Site Scripting (XSS) vulnerability | apasionados | Submission DOM tracking for Contact Form 7 | Medium | 5.9 | 2025-05-07 14:20:37 | Deep Dive |
| CVE-2025-47518 | WordPress Contact Form 7 – PayPal & Stripe Add-on plugin <= 2.3.4 - Cross Site Scripting (XSS) Vulnerability | Scott Paterson | Contact Form 7 – PayPal & Stripe Add-on | Medium | 5.9 | 2025-05-07 14:20:06 | Deep Dive |
| CVE-2025-47491 | WordPress Contact Form Widget plugin <= 1.4.6 - Cross Site Request Forgery (CSRF) Vulnerability | A WP Life | Contact Form Widget | High | 7.4 | 2025-05-07 14:19:53 | Deep Dive |
| CVE-2025-47468 | WordPress Hash Form plugin <= 1.2.8 - Cross Site Request Forgery (CSRF) Vulnerability | hashthemes | Hash Form | Medium | 4.3 | 2025-05-07 14:19:43 | Deep Dive |
| CVE-2025-3851 | Download Manager and Payment Form WordPress Plugin – WP SmartPay 1.1.0 - 2.7.13 - Authenticated (Subscriber+) Information Exposure | themesgrove | Download Manager and Payment Form WordPress Plugin – WP SmartPay | Medium | 4.3 | 2025-05-07 01:43:07 | Deep Dive |
| CVE-2025-3281 | User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.2.1 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion | wpeverest | User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder | Medium | 5.3 | 2025-05-06 07:24:22 | Deep Dive |
| CVE-2025-3815 | SurveyJS <= 1.12.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter | devsoftbaltic | SurveyJS: Drag & Drop Form Builder | Medium | 6.4 | 2025-05-03 07:22:57 | Deep Dive |
| CVE-2024-13381 | Calculated Fields Form < 5.2.62 - Admin+ Stored XSS | Unknown | Calculated Fields Form | - | - | 2025-05-01 06:00:03 | Deep Dive |
| CVE-2024-12273 | Calculated Fields Form < 5.2.62 - Admin+ Stored XSS | Unknown | Calculated Fields Form | - | - | 2025-04-29 06:00:02 | Deep Dive |