Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Basixonline

First CVE: Oct 7, 2019Active for: 7 yearsTotal CVEs: 21
35.1
VTI Score
Medium

Basixonline's vulnerability footprint concentrates in a narrowly scoped web-forms product portfolio, primarily Nex-Forms, which serves as a form-builder and data-collection solution across client sites. The recurring weakness classes—SQL injection, cross-site scripting, missing authorization, improper authentication, and cross-site request forgery—reflect the application-layer input handling and session-management challenges typical of form-processing and user-interaction components exposed in web environments. The vendor's disclosures center on web-application security boundaries and the complexities of handling untrusted user input and maintaining authentication state across form submissions. Defenders should prioritize inventory of deployed form-builder instances and treat input-validation and authentication patches from this vendor as priority updates for web-facing services; current severity, exploitation, and exposure figures are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
3.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Basixonline over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2019
6 years ago
Most Recent CVE
May 8, 2025
443 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-3142HIGH
The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be execute
Sep 19, 20228.854NOYES
CVE-2023-2114HIGH
The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query.
May 8, 20237.245NONO
CVE-2023-52120HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms – Ultimate Form Builder – Contact forms and much more.This issue affects NEX-Forms – Ultimate Form Builder – Cont
Jan 5, 20248.824NONO
CVE-2021-34676HIGH
Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.
Jul 19, 20217.524NONO
CVE-2021-34675HIGH
Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.
Jul 19, 20217.524NONO
CVE-2015-9452CRITICAL
The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter.
Oct 7, 20199.824NONO
CVE-2020-36670MEDIUM
The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including 7.7.1 due to missing capability checks on sev
Mar 7, 20236.322NONO
CVE-2024-53808HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows SQL Injection.This is
Dec 6, 20247.221NONO
CVE-2023-50838HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder – Contact forms and much more.This iss
Dec 28, 20237.221NONO
CVE-2025-4208MEDIUM
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code Execution in all versions up to, and including, 8.9.1 via the
May 8, 20256.320NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
62%
33%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (61.9%)
Unknown0 (0.0%)
Required8 (38.1%)
Privileges Required
Low11 (52.4%)
High5 (23.8%)
None5 (23.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.8% of CVEs· 96th percentile
ExploitDB
1 CVE
4.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Basixonline.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Basixonline — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Basixonline's Products

View all 4 CNAs →

Top CWEs