Arforms
This hub aggregates every CVE we track for Arforms, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
13
CVEs tracked
1
Critical
8
High
0
In CISA KEV
Severity distribution
HIGH8MEDIUM4CRITICAL1
Monthly trend
0
0
0
2
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
2024-092026-08
Latest CVEs
The 13 most recently published vulnerabilities affecting Arforms.
- CVE-2026-57338WordPress ARForms plugin <= 7.1.2 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2024-10504ARForms Builder < 1.7.1 - Unauthenticated Stored XSS5.4
- CVE-2024-54217WordPress ARForms plugin <= 6.4.1 - Subscriber+ Plugin Settings Change vulnerability5.4
- CVE-2024-54216WordPress ARForms plugin < 7.0.2 - Path Traversal vulnerability7.7
- CVE-2024-0427Arforms < 6.4.1 - Reflected XSS6.3
- CVE-2024-32703WordPress ARForms plugin <= 6.4 - Subscriber+ Arbitrary File Deletion vulnerability7.7
- CVE-2024-32704WordPress ARForms plugin <= 6.4 - Subscriber+ Arbitrary WordPress Options Removal vulnerability7.1
- CVE-2024-32705WordPress ARForms plugin <= 6.4 - Subscriber+ Arbitrary Plugin Activation/Deactivation Vulnerability7.1
- CVE-2024-4620ArForms < 6.6 - Unauthenticated RCE9.8
- CVE-2024-4621ArForms < 6.6 - Admin+ Stored XSS4.8
- CVE-2024-32702WordPress ARForms plugin <= 6.4 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2024-32706WordPress ARForms plugin <= 6.4 - Subscriber+ SQL Injection vulnerability8.5
- CVE-2019-16902In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.7.5
Product normalization is registry-driven with AI assist and human review. How it works