Flothemes develops a small portfolio of web-based form and page-building products, with its vulnerability signal centered on application-layer weaknesses including cross-site scripting, improper access control, and related input-handling issues. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flothemes over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0541CRITICAL The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_cu | Apr 25, 2022 | 9.8 | 26 | NO | NO |
CVE-2021-4367MEDIUM The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Options Change by using the flo_import_forms_options AJAX action | Jun 7, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-35095MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Flothemes Flo Forms – Easy Drag & Drop Form Builder plugin <= 1.0.40 versions. | Jun 20, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flothemes.
Media articles that mention a CVE ID that affects a product developed by Flothemes — matched by CVE ID, not by vendor name.