VendorsBasixonlinenex-formsany version
Vulnerabilities

Basixonline Basix NEX-Forms any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2015-9452
The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter.
Published 2019-10-07 · Modified
9.8EPSS 0.024
CVE-2022-3142
NEX-Forms < 7.9.7 - Authenticated SQLi
Published 2022-09-19 · Modified
8.81 PoCEPSS 0.147
CVE-2023-52120
WordPress NEX-Forms – Ultimate Form Builder Plugin <= 8.5.2 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2024-01-05 · Modified
8.8EPSS 0.002
CVE-2024-53808
WordPress NEX-Forms plugin <= 8.7.8 - SQL Injection vulnerability
Published 2024-12-06 · Modified
8.5EPSS 0.006
CVE-2023-50838
WordPress NEX-Forms – Ultimate Form Builder Plugin <= 8.5.5 is vulnerable to SQL Injection
Published 2023-12-28 · Modified
7.6EPSS 0.006
CVE-2021-34675
Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.
Published 2021-07-19 · Modified
7.5EPSS 0.018
CVE-2021-34676
Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.
Published 2021-07-19 · Modified
7.5EPSS 0.018
CVE-2023-2114
NEX-Forms < 8.4 - Admin+ SQL Injection
Published 2023-05-08 · Modified
7.2EPSS 0.446
CVE-2024-47389
WordPress NEX-Forms plugin <= 8.7.3 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-10-05 · Modified
7.1EPSS 0.003
CVE-2024-25593
WordPress NEX-Forms plugin <= 8.5.5 - Cross Site Scripting (XSS) vulnerability
Published 2024-03-15 · Modified
6.5EPSS 0.003
CVE-2024-37512
WordPress NEX-Forms – Ultimate Form Builder plugin <= 8.5.10 - Cross Site Scripting (XSS) vulnerability
Published 2024-07-21 · Analyzed
6.5EPSS 0.003
CVE-2025-3468
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Stored Cross-Site Scripting
Published 2025-05-08 · Analyzed
6.4EPSS 0.002
CVE-2020-36670
NEX-Forms <= 7.7.1 - Missing Authorization on Various AJAX Actions
Published 2023-03-07 · Modified
6.3EPSS 0.006
CVE-2025-4208
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Limited Code Execution via get_table_records Function
Published 2025-05-08 · Analyzed
6.3EPSS 0.003
CVE-2023-0272
NEX-Forms < 8.3.3 - Contributor+ Stored XSS
Published 2023-03-27 · Modified
5.4EPSS 0.005
CVE-2023-0439
NEX-Forms < 8.4.4 - Authenticated Stored XSS
Published 2023-07-17 · Modified
5.4EPSS 0.004
CVE-2024-1129
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_starred()
Published 2024-02-01 · Modified
5.3EPSS 0.006
CVE-2024-1130
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_read()
Published 2024-02-01 · Modified
5.3EPSS 0.006
CVE-2024-0907
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via restore_records()
Published 2024-02-01 · Modified
5.3EPSS 0.006
CVE-2024-10862
NEX-Forms <= 8.7.15 - Authenticated (Admin+) SQL Injection
Published 2024-12-25 · Modified
4.9EPSS 0.006
CVE-2021-24705
NEX-Forms < 8.4.3 - Stored Cross-Site Scripting via CSRF
Published 2021-12-13 · Modified
4.8EPSS 0.003