Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Gravity Forms — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Gravity Forms, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security advisories and vulnerability reports for Gravity Forms, a popular WordPress plugin. It collects documented weaknesses associated with this specific product, covering incidents disclosed over the past several years of release history. Readers can use this aggregation to track how the plugin's security posture has evolved, identify recurring vulnerability classes such as cross-site scripting or privilege escalation, and review the chronological history of disclosed flaws. The data supports security teams in assessing exposure and understanding common attack vectors without needing to parse individual vendor announcements.

Vendor: Rocketgenius Inc.

CVE ID Title CVSS Severity Published
CVE-2026-84434 Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field CWE-434 9.8 Critical 2026-09-19
CVE-2026-16649 Gravity Forms <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via Post Body Field Value CWE-79 7.2 High 2026-09-05
CVE-2026-19513 Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload via State/Chunk Hash Confusion CWE-434 8.1 High 2026-09-01
CVE-2026-12997 Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter CWE-22 7.5 High 2026-07-15
CVE-2026-48866 WordPress Gravity Forms plugin <= 2.10.0.1 - Arbitrary File Deletion vulnerability CWE-22 9.6 Critical 2026-06-01
CVE-2026-5110 Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Single Product Field Inside Repeater CWE-79 7.2 High 2026-05-02
CVE-2026-5111 Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Hidden Product Field in Repeater CWE-79 7.2 High 2026-05-02
CVE-2026-5112 Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Calculation Product Field in Repeater CWE-79 7.2 High 2026-05-02
CVE-2026-5109 Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Product Option CWE-79 7.2 High 2026-05-02
CVE-2026-5113 Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Consent Field Hidden Input CWE-79 7.2 High 2026-05-02
CVE-2026-4406 Gravity Forms <= 2.9.30 - Reflected Cross-Site Scripting via 'form_ids' Parameter CWE-79 4.7 Medium 2026-04-07
CVE-2026-4394 Gravity Forms <= 2.9.30 - Unauthenticated Stored Cross-Site Scripting via Credit Card 'Card Type' Sub-Field CWE-79 6.1 Medium 2026-04-07
CVE-2026-3492 Gravity Forms <= 2.9.28.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title CWE-79 6.4 Medium 2026-03-11
CVE-2025-13407 GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload 9.8AI Critical AI 2025-12-24
CVE-2025-12974 Gravity Forms <= 2.9.21.1 - Unauthenticated Arbitrary File Upload via Legacy Chunked Upload CWE-434 8.1 High 2025-11-18
CVE-2025-12352 Gravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via 'copy_post_image' CWE-434 9.8 Critical 2025-11-07
CVE-2024-13378 GravityForms 2.9.0.1 - 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'style_settings' parameter CWE-79 5.4 Medium 2025-01-17
CVE-2024-13377 GravityForms <= 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'alt' parameter CWE-79 7.2 High 2025-01-17
CVE-2023-28782 WordPress Gravity Forms Plugin <= 2.7.3 is vulnerable to PHP Object Injection CWE-502 8.3 High 2023-12-20

All 19 known CVE vulnerabilities affecting Gravity Forms with full Chinese analysis, references, and POCs where available.