Bitapps develops a modestly represented portfolio of WordPress plugins and form-building tools, including Contact Form Builder, Bit Form, Bit Assist, and File Manager, that serve content management and data-collection workflows across a distributed user base. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and concentrate around the input-handling and file-management boundaries typical of web plugins: path traversal, SQL injection, cross-site scripting, and exposure of sensitive information. The recurring weakness classes reflect the challenges of secure user input validation and access control in plugin architectures where code executes within a shared WordPress environment. Defenders should prioritize patching this vendor's releases for internet-facing WordPress installations, particularly those handling sensitive forms or file uploads; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bitapps over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4774CRITICAL The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types s | May 15, 2023 | 9.8 | 31 | NO | NO |
CVE-2024-43249HIGH Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This issue affects Bit Form Pro: from n/a through 2.6.4. | Aug 19, 2024 | 8.8 | 28 | NO | NO |
CVE-2025-68596HIGH Missing Authorization vulnerability in Bit Apps Bit Assist bit-assist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bit Assist: from n/ | Dec 24, 2025 | 8.8 | 27 | NO | NO |
CVE-2024-7770HIGH The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali | Sep 10, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-7627HIGH The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to | Sep 5, 2024 | 8.1 | 26 | NO | NO |
CVE-2024-7777CRITICAL The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file rea | Aug 20, 2024 | 9.0 | 26 | NO | NO |
CVE-2024-43248CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro allows File Manipulation.This issue affects Bit Form Pro: from | Aug 19, 2024 | 9.1 | 26 | NO | NO |
CVE-2026-25418HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection.This issue affects Bit Form: f | Feb 19, 2026 | 7.6 | 24 | NO | NO |
CVE-2024-47319HIGH Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form bit-form.This issue affects Bit Form: from n/a through <= 2.13.10. | Oct 5, 2024 | 8.0 | 23 | NO | NO |
CVE-2024-47335HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection.This issue affects Bit Form: f | Oct 7, 2024 | 7.6 | 22 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bitapps.
Media articles that mention a CVE ID that affects a product developed by Bitapps — matched by CVE ID, not by vendor name.