Nex Forms
Vendor:
First CVE: Oct 7, 2019 · Active for 6 years
21
Total CVEs
More Total CVEs than 94% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nex Forms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2019
6 years ago
Most Recent CVE
May 8, 2025
444 days ago
CVE Severity & Scoring
Nex Forms21 CVEs
62%
33%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (61.9%)
Unknown0 (0.0%)
Required8 (38.1%)
Privileges Required
Low11 (52.4%)
High5 (23.8%)
None5 (23.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3142HIGH The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be execute | Sep 19, 2022 | 8.8 | 54 | NO | YES |
CVE-2023-2114HIGH The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query. | May 8, 2023 | 7.2 | 45 | NO | NO |
CVE-2023-52120HIGH Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms – Ultimate Form Builder – Contact forms and much more.This issue affects NEX-Forms – Ultimate Form Builder – Cont | Jan 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2021-34676HIGH Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation. | Jul 19, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-34675HIGH Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports. | Jul 19, 2021 | 7.5 | 24 | NO | NO |
CVE-2015-9452CRITICAL The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter. | Oct 7, 2019 | 9.8 | 24 | NO | NO |
CVE-2020-36670MEDIUM The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including 7.7.1 due to missing capability checks on sev | Mar 7, 2023 | 6.3 | 22 | NO | NO |
CVE-2024-53808HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows SQL Injection.This is | Dec 6, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-50838HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder – Contact forms and much more.This iss | Dec 28, 2023 | 7.2 | 21 | NO | NO |
CVE-2025-4208MEDIUM The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code Execution in all versions up to, and including, 8.9.1 via the | May 8, 2025 | 6.3 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.8% of CVEs· 97th percentile
ExploitDB
1 CVE
4.8% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Nex Forms
Top CWEs
Versions
No cataloged versions.