Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Crmperks

First CVE: Jan 24, 2022Active for: 5 yearsTotal CVEs: 41
45.1
VTI Score
High

Crmperks develops a suite of WordPress form-builder plugins and integrations designed to capture, manage, and route contact-form data to CRM platforms such as Zoho. Despite the narrow product focus, these plugins occupy a prominent position in the WordPress ecosystem due to their wide adoption across small-business and enterprise sites. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit tooling; the exposure centers on recurring weakness classes including cross-site scripting, unsafe deserialization, open redirects, SQL injection, and unrestricted file upload—all characteristic of PHP web-application handling of untrusted user input and form submissions. Defenders deploying these plugins should treat security updates as urgent and restrict administrative access; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
41
Total CVEs
More Total CVEs than 98% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Crmperks over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2022
4 years ago
Most Recent CVE
Jul 13, 2026
13 days ago

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-25080MEDIUM
The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing u
Jan 24, 20226.167NONO
CVE-2024-30498CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through
Mar 29, 202410.039NOYES
CVE-2025-7384CRITICAL
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization
Aug 13, 20259.835NONO
CVE-2025-60178CRITICAL
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection.This issue affects WP Gravity Forms HubSpot: from n/a throu
Dec 18, 20259.834NONO
CVE-2025-60090CRITICAL
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gravity Forms Insightly: from n/a
Dec 18, 20259.834NONO
CVE-2021-25079MEDIUM
The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputti
Jan 24, 20226.134NOYES
CVE-2026-9843HIGH
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page fu
Jun 20, 20268.133NONO
CVE-2026-2599CRITICAL
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization
Mar 5, 20269.833NONO
CVE-2025-60089CRITICAL
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Pl
Dec 18, 20259.833NONO
CVE-2026-57421HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms crm-perks-forms allows Reflected XSS.This issue affe
Jul 13, 20267.131NONO
View all 41 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products41 CVEs
51%
20%
29%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.4%)
Network40 (97.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (97.6%)
High1 (2.4%)
Unknown0 (0.0%)
User Interaction
None20 (48.8%)
Unknown0 (0.0%)
Required21 (51.2%)
Privileges Required
Low5 (12.2%)
High5 (12.2%)
None31 (75.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (41 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
7.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Crmperks.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Crmperks — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Crmperks's Products

View all 3 CNAs →

Top CWEs