CVE-2026-4406
- EPSS 0.36%
- Veröffentlicht 07.04.2026 23:25:27
- Zuletzt bearbeitet 24.07.2026 23:10:00
The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This is due to the `GFCommon::send_json()` method ...
CVE-2026-3492
- EPSS 0.2%
- Veröffentlicht 11.03.2026 09:25:43
- Zuletzt bearbeitet 22.04.2026 21:27:27
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a compound failure involving missing authorization on the `create_from_template` AJAX endpoint (allowin...
CVE-2025-12974
- EPSS 0.67%
- Veröffentlicht 18.11.2025 03:27:07
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechanism in all versions up to, and including, 2.9.21.1. This is due to the extension blacklist not inclu...
CVE-2025-12352
- EPSS 1%
- Veröffentlicht 07.11.2025 04:28:53
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to...
CVE-2024-13378
- EPSS 0.29%
- Veröffentlicht 17.01.2025 10:15:07
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter in versions 2.9.0.1 up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possibl...
CVE-2024-13377
- EPSS 0.32%
- Veröffentlicht 17.01.2025 10:15:07
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthent...
CVE-2023-28782
- EPSS 0.62%
- Veröffentlicht 20.12.2023 15:15:07
- Zuletzt bearbeitet 28.04.2026 19:20:09
Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.