| CVE-2024-43220 | WordPress Form Maker by 10Web plugin <= 1.15.26 - Reflected Cross Site Scripting (XSS) vulnerability | 10Web Form Builder Team | Form Maker by 10Web | High | 7.1 | 2024-08-12 21:22:38 | Deep Dive |
| CVE-2024-7484 | CRM Perks Forms <= 1.1.3 - Authenticated (Administrator+) Arbitrary File Upload | crmperks | CRM Perks Forms – WordPress Form Builder | High | 7.2 | 2024-08-06 01:49:57 | Deep Dive |
| CVE-2024-7291 | JetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege Escalation | jetmonsters | JetFormBuilder — Dynamic Blocks Form Builder | High | 7.2 | 2024-08-03 06:41:40 | Deep Dive |
| CVE-2024-7389 | Forminator <= 1.29.1 - HubSpot Developer API Key Sensitive Information Exposure | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | High | 7.5 | 2024-08-02 04:29:55 | Deep Dive |
| CVE-2024-6725 | Formidable Forms <= 6.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting | strategy11team | Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder | Medium | 4.9 | 2024-07-31 10:59:18 | Deep Dive |
| CVE-2024-6770 | Lifetime free Drag & Drop Contact Form Builder for WordPress VForm <= 2.1.5 - Unauthenticated Stored Cross-Site Scripting | vikasratudi | VPSUForm – Drag & Drop Contact Form Builder with Email Automation | High | 7.2 | 2024-07-31 05:30:57 | Deep Dive |
| CVE-2024-3113 | FormFlow < 2.12.2 - Admin+ Stored XSS | Unknown | FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection | - | - | 2024-07-30 06:00:06 | Deep Dive |
| CVE-2024-6703 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Welcome Screen Fields | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Medium | 4.9 | 2024-07-27 12:30:06 | Deep Dive |
| CVE-2024-6518 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Medium | 4.4 | 2024-07-27 11:37:32 | Deep Dive |
| CVE-2024-6520 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Medium | 4.4 | 2024-07-27 11:37:29 | Deep Dive |
| CVE-2024-6521 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Medium | 4.4 | 2024-07-27 11:13:39 | Deep Dive |
| CVE-2024-37512 | WordPress NEX-Forms – Ultimate Form Builder plugin <= 8.5.10 - Cross Site Scripting (XSS) vulnerability | Basix | NEX-Forms – Ultimate Form Builder | Medium | 6.5 | 2024-07-21 07:17:59 | Deep Dive |
| CVE-2024-37920 | WordPress ARForms Form Builder plugin <= 1.6.7 - Reflected Cross Site Scripting (XSS) vulnerability | Repute InfoSystems | ARForms Form Builder | High | 7.1 | 2024-07-20 08:58:54 | Deep Dive |
| CVE-2024-6565 | AForms <= 2.2.6 - Unauthenticated Full Path Disclosure | vividcolorsjp | AForms — Form Builder for Price Calculator & Cost Estimation | Medium | 5.3 | 2024-07-16 08:32:31 | Deep Dive |
| CVE-2024-6313 | Gutenberg Forms <= 2.2.9 - Unauthenticated Arbitrary File Upload | nikolaystrikhar | Gutenberg Forms – WordPress Form Builder Plugin | Critical | 9.8 | 2024-07-09 07:38:47 | Deep Dive |
| CVE-2024-6123 | Bit Form <= 2.13.3 - Authenticated (Administrator+) Arbitrary File Upload | bitpressadmin | Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder | High | 7.2 | 2024-07-09 07:38:45 | Deep Dive |
| CVE-2024-5419 | Void Contact Form 7 Widget For Elementor Page Builder <= 2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via cf7_redirect_page Attribute | voidthemes | Void Contact Form 7 Widget For Elementor Page Builder | Medium | 6.4 | 2024-07-02 03:14:52 | Deep Dive |
| CVE-2022-45803 | WordPress Gutenberg Forms plugin <= 2.2.8.3 - Auth. Broken Access Control vulnerability | Nikolay Strikhar | WordPress Form Builder Plugin – Gutenberg Forms | Medium | 6.5 | 2024-06-21 13:35:51 | Deep Dive |
| CVE-2024-0427 | Arforms < 6.4.1 - Reflected XSS | Unknown | ARForms - Premium WordPress Form Builder Plugin | - | - | 2024-06-12 06:00:02 | Deep Dive |
| CVE-2024-4266 | MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 3.8.8 - Unauthenticated Sensitive Information Exposure | roxnor | MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | Medium | 5.3 | 2024-06-11 07:32:26 | Deep Dive |