| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-68924 | Umbraco Forms 安全漏洞 | Umbraco | Forms | High | 7.5 | 2026-01-16 00:00:00 | Deep Dive |
| CVE-2025-14782 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.49.1 - Missing Authorization to Authenticated (Forminator User+) CSV Export | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Medium | 5.3 | 2026-01-09 06:34:53 | Deep Dive |
| CVE-2025-14803 | Nex-Forms Express WP Form Builder < 9.1.8 - Authenticated Stored XSS | Unknown | NEX-Forms | 中危 | - | 2026-01-09 06:00:13 | Deep Dive |
| CVE-2019-25296 | WP Cost Estimation <= 9.642 - Missing Authorization to Arbitrary File Upload/Delete | loopus | WP Cost Estimation & Payment Forms Builder | Critical | 9.8 | 2026-01-08 02:21:17 | Deep Dive |
| CVE-2019-25295 | WP Cost Estimation < 9.660 - Upload Directory Traversal | loopus | WP Cost Estimation & Payment Forms Builder | Medium | 6.5 | 2026-01-08 01:50:11 | Deep Dive |
| CVE-2025-13722 | Fluent Forms <= 6.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Medium | 5.3 | 2026-01-07 09:21:06 | Deep Dive |
| CVE-2025-13409 | Form Vibes – Database Manager for Forms <= 1.4.13 - Authenticated (Admin+) SQL Injection | wpvibes | Form Vibes – Database Manager for Forms | Medium | 4.9 | 2026-01-06 03:21:38 | Deep Dive |
| CVE-2025-14072 | Ninja Forms < 3.13.3 - Unauthenticated Token Generation and Submission Disclosure | Unknown | Ninja Forms | 高危 | - | 2026-01-02 06:00:12 | Deep Dive |
| CVE-2025-62099 | WordPress Signature Add-On for Gravity Forms plugin <= 1.8.6 - Broken Access Control vulnerability | approveme | Signature Add-On for Gravity Forms | Medium | 4.3 | 2025-12-31 16:41:35 | Deep Dive |
| CVE-2025-69015 | WordPress Crowdsignal Forms plugin <= 1.7.2 - Broken Access Control vulnerability | Automattic | Crowdsignal Forms | Low | 3.8 | 2025-12-30 10:47:54 | Deep Dive |
| CVE-2025-13407 | GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload | Unknown | Gravity Forms | - | - | 2025-12-24 06:00:05 | Deep Dive |
| CVE-2025-60091 | WordPress WP Gravity Forms Zoho CRM and Bigin plugin <= 1.2.9 - Deserialization of untrusted data vulnerability | CRM Perks | WP Gravity Forms Zoho CRM and Bigin | - | - | 2025-12-18 07:22:09 | Deep Dive |
| CVE-2025-60174 | WordPress WP Gravity Forms Constant Contact plugin plugin <= 1.1.2 - Deserialization of untrusted data vulnerability | CRM Perks | WP Gravity Forms Constant Contact Plugin | - | - | 2025-12-18 07:22:09 | Deep Dive |
| CVE-2025-60178 | WordPress WP Gravity Forms HubSpot plugin <= 1.2.6 - Deserialization of untrusted data vulnerability | CRM Perks | WP Gravity Forms HubSpot | - | - | 2025-12-18 07:22:09 | Deep Dive |
| CVE-2025-60180 | WordPress WP Gravity Forms Salesforce plugin <= 1.5.1 - PHP Object Injection vulnerability | CRM Perks | WP Gravity Forms Salesforce | - | - | 2025-12-18 07:22:09 | Deep Dive |
| CVE-2025-60090 | WordPress WP Gravity Forms Insightly plugin <= 1.1.6 - Deserialization of untrusted data vulnerability | CRM Perks | WP Gravity Forms Insightly | - | - | 2025-12-18 07:22:08 | Deep Dive |
| CVE-2025-60084 | WordPress PDF for Elementor Forms + Drag And Drop Template Builder plugin <= 6.5.0 - PHP Object Injection vulnerability | add-ons.org | PDF for Elementor Forms + Drag And Drop Template Builder | High | 8.8 | 2025-12-18 07:22:08 | Deep Dive |
| CVE-2025-60089 | WordPress WP Gravity Forms FreshDesk plugin plugin <= 1.3.5 - Deserialization of untrusted data vulnerability | CRM Perks | WP Gravity Forms FreshDesk Plugin | - | - | 2025-12-18 07:22:08 | Deep Dive |
| CVE-2025-60080 | WordPress PDF for Gravity Forms + Drag And Drop Template Builder plugin <= 6.5.0 - PHP Object Injection vulnerability | add-ons.org | PDF for Gravity Forms + Drag And Drop Template Builder | - | - | 2025-12-18 07:22:07 | Deep Dive |
| CVE-2025-11924 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token | kstover | Ninja Forms – The Contact Form Builder That Grows With You | High | 7.5 | 2025-12-17 06:42:31 | Deep Dive |