Incsub

Forminator

20 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Published 02.07.2025 05:29:17
  • Last modified 07.07.2025 14:22:31

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via deserialization of untrusted input in the 'entry_delete_upload_files' ...

Media report
  • EPSS 0.27%
  • Published 02.07.2025 04:24:56
  • Last modified 07.07.2025 14:28:51

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'entry_delete_upload_files' function in all versions up to, and incl...

  • EPSS 0.04%
  • Published 09.09.2024 05:15:01
  • Last modified 26.03.2025 20:15:21

Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows a crafted URL and accesses the webpage with the web f...

Exploit
  • EPSS 2.74%
  • Published 02.08.2024 05:15:51
  • Last modified 05.02.2025 14:59:01

The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated attackers to extract the HubSpo...

  • EPSS 0.27%
  • Published 23.04.2024 05:15:49
  • Last modified 04.04.2025 13:03:08

Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain user information etc. and alter the page contents on the user's web browser.

  • EPSS 33.33%
  • Published 23.04.2024 05:15:49
  • Last modified 04.04.2025 13:09:27

Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain and alter any information in the database and cause a denial-of-service...

  • EPSS 0.84%
  • Published 23.04.2024 05:15:49
  • Last modified 04.04.2025 13:12:03

Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by accessing files on the server, alter the site that uses th...

  • EPSS 0.13%
  • Published 09.04.2024 19:15:39
  • Last modified 04.02.2025 17:29:45

The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ forminator_form shortcode attribute in versions up to, and including, 1.29.2 due to insufficient input sa...

  • EPSS 2.25%
  • Published 09.04.2024 19:15:19
  • Last modified 28.01.2025 17:23:12

The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) in all versions up to, and including, 1.29.0 due to insufficient input sanitization and output escaping. This makes it possible for...

  • EPSS 0.27%
  • Published 27.03.2024 13:15:49
  • Last modified 05.02.2025 15:40:21

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Reflected XSS.This issue affects Forminator: from n/a through 1.29.0.