| CVE-2026-3445 | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass | properfraction | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | High | 7.1 | 2026-04-04 08:25:20 | Deep Dive |
| CVE-2026-1540 | Spam Protect for Contact Form 7 < 1.2.10 - Editor+ Remote Code Execution | Unknown | Spam Protect for Contact Form 7 | - | - | 2026-04-02 06:00:10 | Deep Dive |
| CVE-2026-4347 | MW WP Form <= 5.1.0 - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir | inc2734 | MW WP Form | High | 8.1 | 2026-04-02 05:28:08 | Deep Dive |
| CVE-2026-3831 | Database for Contact Form 7, WPforms, Elementor forms <= 1.4.9 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode | crmperks | Database for Contact Form 7, WPforms, Elementor forms | Medium | 4.3 | 2026-04-01 01:24:21 | Deep Dive |
| CVE-2026-4257 | Contact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality | supsysticcom | Contact Form by Supsystic | Critical | 9.8 | 2026-03-30 21:26:10 | Deep Dive |
| CVE-2026-5106 | code-projects Exam Form Submission update_fst.php cross site scripting | code-projects | Exam Form Submission | Low | 2.4 | 2026-03-30 04:00:18 | Deep Dive |
| CVE-2026-1307 | Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token | kstover | Ninja Forms – The Contact Form Builder That Grows With You | Medium | 6.5 | 2026-03-28 06:46:09 | Deep Dive |
| CVE-2026-4987 | SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id' | brainstormforce | SureForms – Contact Form, Payment Form & Other Custom Form Builder | High | 7.5 | 2026-03-28 01:25:46 | Deep Dive |
| CVE-2026-4909 | code-projects Exam Form Submission update_s7.php cross site scripting | code-projects | Exam Form Submission | Low | 2.4 | 2026-03-27 02:25:24 | Deep Dive |
| CVE-2026-32532 | WordPress Contact Form & Lead Form Elementor Builder plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerability | ThemeHunk | Contact Form & Lead Form Elementor Builder | 中危 | - | 2026-03-25 16:15:10 | Deep Dive |
| CVE-2026-32527 | WordPress WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin <= 1.1.5 - Broken Access Control vulnerability | CRM Perks | WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms | 中危 | - | 2026-03-25 16:15:09 | Deep Dive |
| CVE-2026-32496 | WordPress Spam Protect for Contact Form 7 plugin <= 1.2.9 - Arbitrary File Deletion vulnerability | NYSL | Spam Protect for Contact Form 7 | 中危 | - | 2026-03-25 16:15:00 | Deep Dive |
| CVE-2026-32483 | WordPress Contact Form Email plugin <= 1.3.63 - Broken Access Control vulnerability | codepeople | Contact Form Email | 中危 | - | 2026-03-25 16:14:58 | Deep Dive |
| CVE-2026-25430 | WordPress Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms plugin <= 1.2.2 - Broken Access Control vulnerability | CRM Perks | Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms | Medium | 6.5 | 2026-03-25 16:14:49 | Deep Dive |
| CVE-2026-25339 | WordPress Contact Form by WPForms plugin <= 1.9.8.7 - Sensitive Data Exposure vulnerability | Syed Balkhi | Contact Form by WPForms | 中危 | - | 2026-03-25 16:14:42 | Deep Dive |
| CVE-2026-4595 | code-projects Exam Form Submission update_s6.php cross site scripting | code-projects | Exam Form Submission | Low | 2.4 | 2026-03-23 18:37:03 | Deep Dive |
| CVE-2026-4578 | code-projects Exam Form Submission update_s3.php cross site scripting | code-projects | Exam Form Submission | Low | 2.4 | 2026-03-23 07:36:26 | Deep Dive |
| CVE-2026-4577 | code-projects Exam Form Submission update_s4.php cross site scripting | code-projects | Exam Form Submission | Low | 2.4 | 2026-03-23 06:35:58 | Deep Dive |
| CVE-2026-4576 | code-projects Exam Form Submission update_s5.php cross site scripting | code-projects | Exam Form Submission | Low | 2.4 | 2026-03-23 05:36:10 | Deep Dive |
| CVE-2026-4575 | code-projects Exam Form Submission update_s2.php cross site scripting | code-projects | Exam Form Submission | Low | 2.4 | 2026-03-23 05:36:08 | Deep Dive |