Formfacade is a web form-building application with a concentrated vulnerability surface centered on its primary product, where the durable signal points to input-handling deficiencies in form processing and page generation. The observed weakness class of cross-site scripting reflects the risks inherent in user-supplied form data and dynamically generated web content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Formfacade over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43313MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in manidoraisamy FormFacade formfacade allows Reflected XSS.This issue affects Fo | Aug 18, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-54301MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in manidoraisamy FormFacade formfacade allows Reflected XSS.This issue affects Fo | Dec 13, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-9613MEDIUM The FormFacade – WordPress plugin for Google Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'userId' and 'publishId' parameters in all versions | Oct 26, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-25934MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormFacade allows Stored XSS.This issue affects FormFacade: from n/a through 1 | Mar 15, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Formfacade.
Media articles that mention a CVE ID that affects a product developed by Formfacade — matched by CVE ID, not by vendor name.