Formbuilder Project maintains a web-based form-creation and management tool with a durable vulnerability profile centered on application-layer input-handling issues, particularly cross-site scripting and cross-site request forgery. These weakness classes reflect the inherent challenges of dynamic web content generation and the importance of rigorous input sanitization and state-change validation in form-handling platforms. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Formbuilder Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0830MEDIUM The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as well as escape its form field v | Apr 4, 2022 | 6.5 | 22 | NO | NO |
CVE-2012-6715MEDIUM The formbuilder plugin before 0.9.1 for WordPress has XSS via a Referer header. | Aug 21, 2019 | 6.1 | 22 | NO | NO |
CVE-2016-10910MEDIUM The formbuilder plugin before 1.06 for WordPress has multiple XSS issues. | Aug 21, 2019 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Formbuilder Project.
Media articles that mention a CVE ID that affects a product developed by Formbuilder Project — matched by CVE ID, not by vendor name.