Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Kali Forms — Contact Form & Drag-and-Drop Builder — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Kali Forms — Contact Form & Drag-and-Drop Builder, with AI-generated Chinese analysis, references, and POCs.

This page details security vulnerabilities associated with the Kali Forms contact form plugin developed by Webcraftic. It aggregates reports of weaknesses such as cross-site scripting, broken access control, and other common application security flaws found within the software. The database covers vulnerabilities disclosed from 2021 to the present, providing a comprehensive view of the product's security posture over time. Users can leverage this resource to track official advisories from the vendor, understand the specific characteristics of each weakness class, and review the historical record of identified issues for this particular product. By analyzing these entries, security professionals, auditors, and developers can assess the current risk level, verify if specific patches have been applied, and make informed decisions about integrating or maintaining the plugin in their environments. This aggregation serves as a centralized reference point for understanding the evolution of security defects in Kali Forms, highlighting patterns in vulnerability discovery and resolution. The data is sourced from public vulnerability databases and vendor notifications, ensuring that the information remains accurate and up-to-date for those conducting threat modeling or compliance checks.

Vendor: wpchill

CVE ID Title CVSS Severity Published
CVE-2026-16144 Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameter CWE-94 8.1 High 2026-08-01
CVE-2026-15395 Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value CWE-79 7.2 High 2026-07-17
CVE-2026-11579 Kali Forms < 2.4.17 - Unauthenticated Media Upload - - 2026-07-15
CVE-2026-11580 Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR - - 2026-07-15
CVE-2026-9107 Kali Forms <= 2.4.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'kaliforms_field_components' Parameter CWE-79 6.4 Medium 2026-07-01
CVE-2026-11581 Kali Forms < 2.4.13 - Contributor+ Stored XSS via Form Field Caption - - 2026-06-30
CVE-2026-3584 Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process CWE-94 9.8 Critical 2026-03-20
CVE-2026-1860 Kali Forms <= 2.4.8 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposure CWE-862 4.3 Medium 2026-02-18
CVE-2024-1218 Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization CWE-862 4.3 Medium 2024-02-20
CVE-2024-1217 Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin Deactivation CWE-862 7.6 High 2024-02-20
CVE-2020-36717 Kali Forms <= 2.1.1 - Cross-Site Request Forgery CWE-352 8.8 High 2023-06-07
CVE-2020-36720 Kali Forms <= 2.1.1 - Missing Authorization to Settings Update CWE-862 7.1 High 2023-06-07
CVE-2020-36712 Kali Forms <= 2.1.1 - Unauthenticated Arbitrary Post Deletion CWE-862 8.6 High 2023-06-07

All 13 known CVE vulnerabilities affecting Kali Forms — Contact Form & Drag-and-Drop Builder with full Chinese analysis, references, and POCs where available.