Basixonline's vulnerability footprint concentrates in a narrowly scoped web-forms product portfolio, primarily Nex-Forms, which serves as a form-builder and data-collection solution across client sites. The recurring weakness classes—SQL injection, cross-site scripting, missing authorization, improper authentication, and cross-site request forgery—reflect the application-layer input handling and session-management challenges typical of form-processing and user-interaction components exposed in web environments. The vendor's disclosures center on web-application security boundaries and the complexities of handling untrusted user input and maintaining authentication state across form submissions. Defenders should prioritize inventory of deployed form-builder instances and treat input-validation and authentication patches from this vendor as priority updates for web-facing services; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Basixonline over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3142HIGH The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be execute | Sep 19, 2022 | 8.8 | 54 | NO | YES |
CVE-2023-2114HIGH The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query. | May 8, 2023 | 7.2 | 45 | NO | NO |
CVE-2023-52120HIGH Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms – Ultimate Form Builder – Contact forms and much more.This issue affects NEX-Forms – Ultimate Form Builder – Cont | Jan 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2021-34676HIGH Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation. | Jul 19, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-34675HIGH Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports. | Jul 19, 2021 | 7.5 | 24 | NO | NO |
CVE-2015-9452CRITICAL The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter. | Oct 7, 2019 | 9.8 | 24 | NO | NO |
CVE-2020-36670MEDIUM The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including 7.7.1 due to missing capability checks on sev | Mar 7, 2023 | 6.3 | 22 | NO | NO |
CVE-2024-53808HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows SQL Injection.This is | Dec 6, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-50838HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder – Contact forms and much more.This iss | Dec 28, 2023 | 7.2 | 21 | NO | NO |
CVE-2025-4208MEDIUM The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code Execution in all versions up to, and including, 8.9.1 via the | May 8, 2025 | 6.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Basixonline.
Media articles that mention a CVE ID that affects a product developed by Basixonline — matched by CVE ID, not by vendor name.