Gravityforms

Gravity Forms

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 1%
  • Veröffentlicht 07.11.2025 04:28:53
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to...

  • EPSS 0.32%
  • Veröffentlicht 17.01.2025 10:15:07
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthent...

  • EPSS 0.29%
  • Veröffentlicht 17.01.2025 10:15:07
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter in versions 2.9.0.1 up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possibl...

  • EPSS 0.62%
  • Veröffentlicht 20.12.2023 15:15:07
  • Zuletzt bearbeitet 28.04.2026 19:20:09

Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.