| CVE-2024-10504 | ARForms Builder < 1.7.1 - Unauthenticated Stored XSS | Unknown | Contact Form, Survey, Quiz & Popup Form Builder | - | - | 2025-05-15 20:06:44 | Deep Dive |
| CVE-2024-10475 | Lead Form Builder < 1.9.8 - Admin+ Stored XSS | Unknown | Responsive Contact Form Builder & Lead Generation Plugin | - | - | 2025-05-15 20:06:43 | Deep Dive |
| CVE-2025-3794 | WPForms Lite <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parameter | smub | WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More | Medium | 5.4 | 2025-05-09 22:22:13 | Deep Dive |
| CVE-2025-47626 | WordPress Submission DOM tracking for Contact Form 7 plugin <= 2.1 - Cross Site Scripting (XSS) vulnerability | apasionados | Submission DOM tracking for Contact Form 7 | Medium | 5.9 | 2025-05-07 14:20:37 | Deep Dive |
| CVE-2025-47518 | WordPress Contact Form 7 – PayPal & Stripe Add-on plugin <= 2.3.4 - Cross Site Scripting (XSS) Vulnerability | Scott Paterson | Contact Form 7 – PayPal & Stripe Add-on | Medium | 5.9 | 2025-05-07 14:20:06 | Deep Dive |
| CVE-2025-47491 | WordPress Contact Form Widget plugin <= 1.4.6 - Cross Site Request Forgery (CSRF) Vulnerability | A WP Life | Contact Form Widget | High | 7.4 | 2025-05-07 14:19:53 | Deep Dive |
| CVE-2025-3912 | WS Form LITE – Drag & Drop Contact Form Builder for WordPress <= 1.10.35 - Missing Authorization to Unauthenticated Sensitive Information Exposure | westguard | WS Form LITE – Drag & Drop Contact Form Builder | Medium | 5.3 | 2025-04-25 11:12:52 | Deep Dive |
| CVE-2025-2580 | Contact Form by Bit Form <= 2.18.3 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | bitpressadmin | Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder | Medium | 4.9 | 2025-04-25 05:25:06 | Deep Dive |
| CVE-2025-46510 | WordPress Contact Form 7 Calendar plugin <= 3.0.1 - CSRF to Stored XSS vulnerability | harrysudana | Contact Form 7 Calendar | High | 7.1 | 2025-04-24 16:08:55 | Deep Dive |
| CVE-2025-46252 | WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.2 - SQL Injection vulnerability | Kofi Mokome | Message Filter for Contact Form 7 | High | 7.6 | 2025-04-22 09:53:35 | Deep Dive |
| CVE-2025-39521 | WordPress Contact Form vCard Generator plugin <= 2.4 - Reflected Cross Site Scripting (XSS) vulnerability | Ashish Ajani | Contact Form vCard Generator | High | 7.1 | 2025-04-17 15:46:56 | Deep Dive |
| CVE-2025-3487 | Forminator <= 1.42.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'limit' | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Medium | 6.4 | 2025-04-17 11:13:06 | Deep Dive |
| CVE-2025-3479 | Forminator <= 1.42.0 - Order Replay Vulnerability | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Medium | 5.3 | 2025-04-17 11:13:06 | Deep Dive |
| CVE-2025-3615 | Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Medium | 6.4 | 2025-04-17 07:34:08 | Deep Dive |
| CVE-2025-3247 | Contact Form 7 <= 6.0.5 - Order Replay Vulnerability | rocklobsterinc | Contact Form 7 | Medium | 5.3 | 2025-04-16 05:23:01 | Deep Dive |
| CVE-2024-13452 | Contact Form by Supsystic <= 1.7.29 - Cross-Site Request Forgery to Stored Cross-Site Scripting via saveAsCopy AJAX Action | supsysticcom | Contact Form by Supsystic | Medium | 6.1 | 2025-04-16 02:12:04 | Deep Dive |
| CVE-2025-3421 | Everest Forms <= 3.1.1 - Reflected Cross-Site Scripting | wpeverest | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | Medium | 6.1 | 2025-04-11 12:42:25 | Deep Dive |
| CVE-2025-3439 | Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 - Unauthenticated PHP Object Injection | wpeverest | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | Critical | 9.8 | 2025-04-11 12:42:24 | Deep Dive |
| CVE-2025-3422 | Everest Forms <= 3.1.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution | wpeverest | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | Medium | 5.4 | 2025-04-11 12:42:24 | Deep Dive |
| CVE-2025-32199 | WordPress Contact Form Builder by vcita plugin <= 4.10.2 - Cross Site Scripting (XSS) vulnerability | eyale-vc | Contact Form Builder by vcita | Medium | 6.5 | 2025-04-10 08:09:44 | Deep Dive |