Sureforms

Vendor:

First CVE: Jan 8, 2025 · Active for 1 year

7
Total CVEs
More Total CVEs than 83% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 15% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Sureforms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 8, 2025
18 months ago
Most Recent CVE
Aug 1, 2025
357 days ago

CVE Severity & Scoring

Sureforms7 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (71.4%)
High2 (28.6%)
Unknown0 (0.0%)
User Interaction
None2 (28.6%)
Unknown0 (0.0%)
Required5 (71.4%)
Privileges Required
Low0 (0.0%)
High3 (42.9%)
None4 (57.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_
Jul 9, 20258.125NONO
The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could
Aug 1, 20255.821NONO
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.3 via the use of file_
Jul 9, 20257.519NONO
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_expor
Jan 8, 20255.317NONO
The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to
Apr 30, 20254.916NONO
The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Si
May 2, 20253.515NONO
The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Si
May 2, 20253.515NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Sureforms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.5.027.80.7%00