Gravityforms maintains a WordPress form-builder plugin with a narrowly scoped product footprint centered on form handling and data capture for WordPress sites. The observed vulnerability signal centers on deserialization of untrusted data, a mechanism endemic to plugins that persist and reconstruct user-submitted form states. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gravityforms over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-12997HIGH The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This ma | Jul 15, 2026 | 7.5 | 34 | NO | NO |
CVE-2025-12352CRITICAL The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and incl | Nov 7, 2025 | 9.8 | 34 | NO | NO |
CVE-2023-28782CRITICAL Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3. | Dec 20, 2023 | 9.8 | 31 | NO | NO |
CVE-2026-5111HIGH The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output | May 2, 2026 | 7.2 | 30 | NO | NO |
CVE-2026-5110HIGH The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input valida | May 2, 2026 | 7.2 | 30 | NO | NO |
CVE-2026-5109HIGH The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escapi | May 2, 2026 | 7.2 | 30 | NO | NO |
CVE-2026-5113HIGH The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.10.0. This is due to a flawed | May 2, 2026 | 7.2 | 29 | NO | NO |
CVE-2026-5112HIGH The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input valida | May 2, 2026 | 7.2 | 29 | NO | NO |
CVE-2025-12974HIGH The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechanism in all versions up to, and | Nov 18, 2025 | 8.1 | 29 | NO | NO |
CVE-2026-4394MEDIUM The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`) in all versions up to, and in | Apr 8, 2026 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gravityforms.
Media articles that mention a CVE ID that affects a product developed by Gravityforms — matched by CVE ID, not by vendor name.