| CVE-2025-7697 | Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 - Unauthenticated PHP Object Injection via verify_field_val Function | crmperks | Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms | Critical | 9.8 | 2025-07-19 04:23:03 | Deep Dive |
| CVE-2025-7696 | Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.2.3 - Unauthenticated PHP Object Injection via verify_field_val Function | crmperks | Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms | Critical | 9.8 | 2025-07-19 04:23:02 | Deep Dive |
| CVE-2025-49485 | Extension - balbooa.com - SQL injection in Balbooa Forms component version 1.0.0 - 2.3.1.1 for Joomla | balbooa.com | Balbooa Forms component for Joomla | 高危 | - | 2025-07-18 09:51:02 | Deep Dive |
| CVE-2025-7638 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.45.0 - Authenticated (Administrator+) SQL Injection via `order_by` Parameter | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Medium | 4.9 | 2025-07-18 04:23:02 | Deep Dive |
| CVE-2025-5392 | GB Forms DB <= 1.0.2 - Unauthenticated Remote Code Execution | gb-plugins | GB Forms DB | Critical | 9.8 | 2025-07-11 06:43:34 | Deep Dive |
| CVE-2025-6782 | GoZen Forms <= 1.1.5 - Unauthenticated SQL Injection via dirGZActiveForm() | optinlyhq | GoZen Forms | High | 7.5 | 2025-07-04 01:44:06 | Deep Dive |
| CVE-2025-6783 | GoZen Forms <= 1.1.5 - Unauthenticated SQL Injection via emdedSc() | optinlyhq | GoZen Forms | High | 7.5 | 2025-07-04 01:44:05 | Deep Dive |
| CVE-2025-6464 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | High | 7.5 | 2025-07-02 05:29:17 | Deep Dive |
| CVE-2025-6463 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | High | 8.8 | 2025-07-02 04:24:56 | Deep Dive |
| CVE-2025-53279 | WordPress Popup addon for Ninja Forms plugin <= 3.4 - Cross Site Scripting (XSS) Vulnerability | Aman | Popup addon for Ninja Forms | Medium | 6.5 | 2025-06-27 13:21:20 | Deep Dive |
| CVE-2025-53263 | WordPress Address Autocomplete via Google for Gravity Forms plugin <= 1.3.4 - Cross Site Request Forgery (CSRF) Vulnerability | PluginsCafe | Address Autocomplete via Google for Gravity Forms | Medium | 5.4 | 2025-06-27 13:21:09 | Deep Dive |
| CVE-2025-47654 | WordPress FormLift for Infusionsoft Web Forms plugin <= 7.5.20 - Reflected Cross Site Scripting (XSS) vulnerability | Adrian Tobey | FormLift for Infusionsoft Web Forms | High | 7.1 | 2025-06-27 11:52:33 | Deep Dive |
| CVE-2025-5398 | Ninja Forms <= 3.10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via CSTI | kstover | Ninja Forms – The Contact Form Builder That Grows With You | Medium | 6.4 | 2025-06-27 09:23:19 | Deep Dive |
| CVE-2025-5927 | Everest Forms (Pro) <= 1.9.4 - Unauthenticated Path Traversal to Arbitrary File Deletion | WPEverest | Everest Forms Pro | High | 7.5 | 2025-06-25 09:21:41 | Deep Dive |
| CVE-2025-49880 | WordPress CubeWP Forms plugin <= 1.1.5 - Broken Access Control Vulnerability | Imran Tauqeer | CubeWP Forms | Medium | 4.3 | 2025-06-17 15:01:13 | Deep Dive |
| CVE-2025-30953 | WordPress WP Gravity Forms Salesforce plugin <= 1.4.7 - Open Redirection Vulnerability | CRM Perks | WP Gravity Forms Salesforce | Medium | 4.7 | 2025-06-06 12:54:11 | Deep Dive |
| CVE-2025-30954 | WordPress WP Gravity Forms Constant Contact Plugin <= 1.1.0 - Open Redirection Vulnerability | CRM Perks | WP Gravity Forms Constant Contact Plugin | Medium | 4.7 | 2025-06-06 12:54:10 | Deep Dive |
| CVE-2025-49283 | WordPress Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant plugin <= 4.1.1 - Cross Site Request Forgery (CSRF) Vulnerability | Matthias Nordwig | Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant | Medium | 4.3 | 2025-06-06 12:53:41 | Deep Dive |
| CVE-2025-48329 | WordPress Real Time Validation for Gravity Forms plugin <= 1.7.0 - Reflected Cross Site Scripting (XSS) vulnerability | Daman Jeet | Real Time Validation for Gravity Forms | High | 7.1 | 2025-06-06 11:48:59 | Deep Dive |
| CVE-2025-48328 | WordPress Real Time Validation for Gravity Forms plugin <= 1.7.0 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | Daman Jeet | Real Time Validation for Gravity Forms | Medium | 4.3 | 2025-06-06 11:37:52 | Deep Dive |