| CVE-2025-10498 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion | kstover | Ninja Forms – The Contact Form Builder That Grows With You | Medium | 4.3 | 2025-09-27 02:25:14 | Deep Dive |
| CVE-2025-10499 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update | kstover | Ninja Forms – The Contact Form Builder That Grows With You | Medium | 4.3 | 2025-09-27 02:25:13 | Deep Dive |
| CVE-2025-60166 | WordPress WP Subscription Forms PRO Plugin <= 2.0.5 - Arbitrary Content Deletion Vulnerability | wpshuffle | WP Subscription Forms PRO | Medium | 4.3 | 2025-09-26 08:32:03 | Deep Dive |
| CVE-2025-59549 | WordPress GetResponse Forms Plugin <= 2.6.0 - Cross Site Scripting (XSS) Vulnerability | fatcatapps | GetResponse Forms | Medium | 6.5 | 2025-09-22 18:26:07 | Deep Dive |
| CVE-2025-57933 | WordPress Piotnet Forms Plugin <= 1.0.30 - Cross Site Request Forgery (CSRF) Vulnerability | piotnetdotcom | Piotnet Forms | Medium | 4.3 | 2025-09-22 18:25:04 | Deep Dive |
| CVE-2025-58006 | WordPress WP Gravity Forms Keap/Infusionsoft plugin <= 1.2.6 - Open Redirection vulnerability | CRM Perks | WP Gravity Forms Keap/Infusionsoft | Medium | 4.7 | 2025-09-22 18:24:12 | Deep Dive |
| CVE-2025-10489 | SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form Creation | brainstormforce | SureForms – Contact Form, Payment Form & Other Custom Form Builder | Medium | 4.3 | 2025-09-20 04:27:55 | Deep Dive |
| CVE-2025-9083 | Ninja-forms < 3.11.1 - Unauthenticated PHP Objection | Unknown | Ninja Forms | - | - | 2025-09-18 06:00:06 | Deep Dive |
| CVE-2025-58842 | WordPress Donation Forms WP by Givecloud Plugin <= 1.0.9 - Cross Site Scripting (XSS) Vulnerability | givecloud | Donation Forms WP by Givecloud | Medium | 6.5 | 2025-09-05 13:45:31 | Deep Dive |
| CVE-2025-58639 | WordPress Contact Form By Mega Forms Plugin <= 1.6.1 - Broken Access Control Vulnerability | Ali Khallad | Contact Form By Mega Forms | Medium | 5.4 | 2025-09-03 14:36:57 | Deep Dive |
| CVE-2025-9260 | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Medium | 6.5 | 2025-09-02 23:22:46 | Deep Dive |
| CVE-2025-9441 | iATS Online Forms <= 1.2 - Authenticated (Contributor+) SQL Injection via order Parameter | iatspaymentsdev | iATS Online Forms | Medium | 6.5 | 2025-08-29 04:25:30 | Deep Dive |
| CVE-2025-49387 | WordPress Drag and Drop File Upload for Elementor Forms Plugin <= 1.5.3 - Arbitrary File Upload Vulnerability | add-ons.org | Drag and Drop File Upload for Elementor Forms | Critical | 10.0 | 2025-08-28 12:37:13 | Deep Dive |
| CVE-2025-58208 | WordPress PDF for Elementor Forms + Drag And Drop Template Builder Plugin <= 6.2.0 - Cross Site Scripting (XSS) Vulnerability | add-ons.org | PDF for Elementor Forms + Drag And Drop Template Builder | Medium | 6.5 | 2025-08-27 17:45:47 | Deep Dive |
| CVE-2025-49399 | WordPress NEX-Forms Plugin <= 9.1.3 - Cross Site Request Forgery (CSRF) Vulnerability | Basix | NEX-Forms | High | 8.8 | 2025-08-20 08:03:50 | Deep Dive |
| CVE-2025-8896 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting | cozmoslabs | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | Medium | 6.4 | 2025-08-16 06:39:22 | Deep Dive |
| CVE-2025-54682 | WordPress Connector for Gravity Forms and Google Sheets Plugin plugin <= 1.2.4 - Cross Site Request Forgery (CSRF) Vulnerability | CRM Perks | Connector for Gravity Forms and Google Sheets | Medium | 5.4 | 2025-08-14 10:34:46 | Deep Dive |
| CVE-2025-54681 | WordPress Connector for Gravity Forms and Google Sheets Plugin plugin <= 1.2.4 - Open Redirection Vulnerability | CRM Perks | Connector for Gravity Forms and Google Sheets | Medium | 4.7 | 2025-08-14 10:34:45 | Deep Dive |
| CVE-2025-24775 | WordPress Forms <= 2.9.0 - Arbitrary File Upload Vulnerability | Made I.T. | Forms | Critical | 9.9 | 2025-08-14 10:34:36 | Deep Dive |
| CVE-2025-7384 | Database for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP Object Injection to Arbitrary File Deletion | crmperks | Database for Contact Form 7, WPforms, Elementor forms | Critical | 9.8 | 2025-08-13 04:22:57 | Deep Dive |