Forminator forms
This hub aggregates every CVE we track for Forminator forms, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM9HIGH1
Monthly trend
0
4
0
0
1
2
0
2
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 10 most recently published vulnerabilities affecting Forminator forms.
- CVE-2025-5341Forminator <= 1.44.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via id and data-size Parameters6.4
- CVE-2025-3479Forminator <= 1.42.0 - Order Replay Vulnerability5.3
- CVE-2025-3487Forminator <= 1.42.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'limit'6.4
- CVE-2025-0469Forminator <= 1.39.2 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
- CVE-2024-7052Forminator < 1.38.3 - Admin+ Stored XSS4.8
- CVE-2025-0470Forminator <= 1.38.2 - Reflected Cross-Site Scripting via Title Parameter6.1
- CVE-2024-9700Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.36.0 - Insecure Direct Object Reference to Submission Manipulation5.3
- CVE-2024-10402Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation7.5
- CVE-2024-9351Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Quiz Creation4.3
- CVE-2024-9352Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Custom Form Creation4.3
Product normalization is registry-driven with AI assist and human review. How it works