| CVE-2024-12201 | Hash Form <= 1.2.1 - Missing Authorization to Authenticated (Contributor+) Form Style Creation | hashthemes | Hash Form – Drag & Drop Form Builder | Medium | 4.3 | 2024-12-12 06:46:34 | Deep Dive |
| CVE-2024-11052 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations | kstover | Ninja Forms – The Contact Form Builder That Grows With You | High | 7.2 | 2024-12-12 05:24:24 | Deep Dive |
| CVE-2024-11205 | WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation | smub | WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More | High | 8.5 | 2024-12-10 04:23:41 | Deep Dive |
| CVE-2024-54223 | WordPress ARForms plugin <= 1.7.1 - HTML Injection vulnerability | reputeinfosystems | ARForms Form Builder | Medium | 5.3 | 2024-12-09 11:31:59 | Deep Dive |
| CVE-2024-10056 | Contact Form Builder <= 4.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via livesite-pay Shortcode | eyale-vc | Contact Form Builder by vcita | Medium | 6.4 | 2024-12-05 09:23:07 | Deep Dive |
| CVE-2024-5020 | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-12-04 08:22:47 | Deep Dive |
| CVE-2024-11897 | Contact Form, Survey & Form Builder – MightyForms <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting | mightyforms | Contact Form, Survey & Form Builder – MightyForms | Medium | 6.4 | 2024-12-04 02:40:27 | Deep Dive |
| CVE-2024-10587 | Funnelforms Free <= 3.7.5.1 - Authenticated (Contributor+) PHP Object Injection | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | High | 8.8 | 2024-12-04 02:40:25 | Deep Dive |
| CVE-2024-11188 | Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.16.1.2 - Reflected Cross-Site Scripting via Custom HTML Form Parameter | strategy11team | Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder | Medium | 6.1 | 2024-11-23 05:40:11 | Deep Dive |
| CVE-2024-11332 | HIPAA Compliant Forms with Drag’n’Drop HIPAA Form Builder. Sign HIPAA documents <= 1.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | hipaatizer | HIPAA Compliant Forms with Drag’n’Drop HIPAA Form Builder. Sign HIPAA documents | Medium | 6.4 | 2024-11-23 04:32:21 | Deep Dive |
| CVE-2024-10260 | Tripetto <= 8.0.11 - Unauthentiated Stored Cross-Site Scripting via Form File Upload | tripetto | WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto | High | 7.2 | 2024-11-15 05:30:56 | Deep Dive |
| CVE-2024-10593 | WPForms – Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion | smub | WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More | Medium | 4.3 | 2024-11-13 02:33:17 | Deep Dive |
| CVE-2024-10265 | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.30 - Reflected Cross-Site Scripting via add_query_arg Parameter | 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | Medium | 6.1 | 2024-11-10 12:30:34 | Deep Dive |
| CVE-2024-8756 | Quform - WordPress Form Builder <= 2.20.0 - Unauthenticated Sensitive Information Exposure | ThemeCatcher | Quform - WordPress Form Builder | Medium | 5.3 | 2024-11-09 05:40:23 | Deep Dive |
| CVE-2024-10647 | WS Form LITE – Drag & Drop Contact Form Builder for WordPress <= 1.9.244 - Reflected Cross-Site Scripting via URL | westguard | WS Form LITE – Drag & Drop Contact Form Builder | Medium | 6.1 | 2024-11-06 02:01:57 | Deep Dive |
| CVE-2024-9700 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.36.0 - Insecure Direct Object Reference to Submission Manipulation | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Medium | 5.3 | 2024-10-31 05:31:24 | Deep Dive |
| CVE-2024-10402 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | High | 7.5 | 2024-10-26 11:38:03 | Deep Dive |
| CVE-2024-9352 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Custom Form Creation | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Medium | 4.3 | 2024-10-17 05:33:09 | Deep Dive |
| CVE-2024-9351 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Quiz Creation | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Medium | 4.3 | 2024-10-17 05:33:09 | Deep Dive |
| CVE-2017-20194 | Formidable Form Builder < 2.05.03 - Unauthenticated Information Disclosure | strategy11team | Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder | Medium | 5.3 | 2024-10-16 07:31:53 | Deep Dive |