Convert Forms Project maintains a web form-building and data-capture application where vulnerabilities center on input-handling and file-upload controls, manifesting as cross-site scripting, SQL injection, and unrestricted file-upload issues. Live severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Convert Forms Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10063HIGH The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that is mishandled when exporting a Leads file. | Apr 12, 2018 | 7.8 | 39 | NO | YES |
CVE-2024-40744CRITICAL Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8. | Dec 4, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-40745MEDIUM Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8. | Dec 4, 2024 | 5.4 | 16 | NO | NO |
A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL command | Mar 5, 2025 | 2.7 | 12 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Convert Forms Project.
Media articles that mention a CVE ID that affects a product developed by Convert Forms Project — matched by CVE ID, not by vendor name.