VendorsWPMU DEVforminator_formsany version
Vulnerabilities

WPMU DEV Forminator Forms any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2024-10402
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation
Published 2024-10-26 · Analyzed
8.8EPSS 0.005
CVE-2025-3487
Forminator <= 1.42.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'limit'
Published 2025-04-17 · Analyzed
6.4EPSS 0.003
CVE-2025-5341
Forminator <= 1.44.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via id and data-size Parameters
Published 2025-06-05 · Analyzed
6.4EPSS 0.003
CVE-2025-0469
Forminator <= 1.39.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2025-02-27 · Analyzed
6.4EPSS 0.003
CVE-2025-0470
Forminator <= 1.38.2 - Reflected Cross-Site Scripting via Title Parameter
Published 2025-01-31 · Analyzed
6.1EPSS 0.003
CVE-2024-9700
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.36.0 - Insecure Direct Object Reference to Submission Manipulation
Published 2024-10-31 · Analyzed
5.3EPSS 0.004
CVE-2025-3479
Forminator <= 1.42.0 - Order Replay Vulnerability
Published 2025-04-17 · Analyzed
5.3EPSS 0.002
CVE-2024-7052
Forminator < 1.38.3 - Admin+ Stored XSS
Published 2025-02-14 · Analyzed
4.8EPSS 0.003
CVE-2024-9351
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Quiz Creation
Published 2024-10-17 · Analyzed
4.3EPSS 0.002
CVE-2024-9352
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Custom Form Creation
Published 2024-10-17 · Analyzed
4.3EPSS 0.002