CVE-2026-92144
- EPSS 0.55%
- Veröffentlicht 01.10.2026 09:26:58
- Zuletzt bearbeitet 01.10.2026 15:17:35
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in all versions up to, and including, 1.57.2 due to insufficient input s...
CVE-2026-85235
- EPSS 0.28%
- Veröffentlicht 01.10.2026 08:28:42
- Zuletzt bearbeitet 01.10.2026 19:17:25
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.2 due to insufficient input sanitization...
CVE-2026-92229
- EPSS 0.4%
- Veröffentlicht 19.09.2026 02:27:10
- Zuletzt bearbeitet 21.09.2026 13:33:33
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an act...
CVE-2026-18324
- EPSS 0.3%
- Veröffentlicht 28.08.2026 03:39:34
- Zuletzt bearbeitet 28.08.2026 16:17:07
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitizati...
CVE-2026-18328
- EPSS 0.24%
- Veröffentlicht 25.08.2026 07:39:50
- Zuletzt bearbeitet 26.08.2026 16:19:05
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 1.57.0 due to insuffici...
CVE-2026-18323
- EPSS 0.31%
- Veröffentlicht 25.08.2026 07:39:50
- Zuletzt bearbeitet 26.08.2026 16:19:05
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) in all versions up to, and including, 1.57.0.2 due to insufficient inp...
CVE-2026-15748
- EPSS 1.18%
- Veröffentlicht 18.08.2026 05:31:20
- Zuletzt bearbeitet 20.08.2026 12:48:10
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dange...
CVE-2026-12998
- EPSS 0.3%
- Veröffentlicht 16.08.2026 06:38:07
- Zuletzt bearbeitet 20.08.2026 12:48:10
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.55.0.2 via the 'draft' parameter due to missing validation on a use...
CVE-2026-18325
- EPSS 0.28%
- Veröffentlicht 06.08.2026 03:26:08
- Zuletzt bearbeitet 12.08.2026 21:00:52
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input...
CVE-2026-6214
- EPSS 0.44%
- Veröffentlicht 07.05.2026 04:16:35
- Zuletzt bearbeitet 07.05.2026 14:00:05
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_for_saving_export_schedule() function in library/class-export.php failing to perform a capability check...