Funnelforms is a form-building platform with a modest vulnerability footprint concentrated in its core product and free tier offering. The recurring weakness classes—missing authorization, cross-site request forgery, path traversal, and unrestricted file uploads—reflect common application-layer input-handling and access-control shortcomings in web-based form and workflow tools. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Funnelforms over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68582HIGH Missing Authorization vulnerability in Funnelforms Funnelforms Free funnelforms-free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Funn | Dec 24, 2025 | 8.8 | 27 | NO | NO |
CVE-2024-6311HIGH The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'af2_add_font' function in all versions up to, and incl | Aug 28, 2024 | 7.2 | 22 | NO | NO |
CVE-2025-62758MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Funnelforms Funnelforms Free funnelforms-free allows DOM-Based XSS.This issue | Dec 31, 2025 | 6.5 | 21 | NO | NO |
CVE-2024-6312MEDIUM The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 3.7.3.2 via the 'af2DeleteFontFile' function. This is due t | Aug 28, 2024 | 6.5 | 21 | NO | NO |
CVE-2023-4950MEDIUM The Interactive Contact Form and Multi Step Form Builder WordPress plugin before 3.4 does not sanitise and escape some parameters, which could allow unauthenticated users to perfor | Oct 16, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-5990MEDIUM The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor WordPress plugin before 3.4.2 does not have CSRF checks on some of its form actions such as deletio | Dec 4, 2023 | 6.5 | 19 | NO | NO |
CVE-2024-5857MEDIUM The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized loss of data due to a missing | Aug 29, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-7447MEDIUM The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a | Aug 28, 2024 | 5.3 | 17 | NO | NO |
CVE-2023-5385MEDIUM The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_copy_posts function in versions up to, an | Nov 22, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-5419MEDIUM The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_test_mail function in versions up to, | Nov 22, 2023 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Funnelforms.
Media articles that mention a CVE ID that affects a product developed by Funnelforms — matched by CVE ID, not by vendor name.