Gravity Forms
Vendor:
First CVE: Dec 20, 2023 · Active for 2 years
14
Total CVEs
More Total CVEs than 91% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gravity Forms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2023
2 years ago
Most Recent CVE
Jul 15, 2026
9 days ago
CVE Severity & Scoring
Gravity Forms14 CVEs
29%
57%
14%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (78.6%)
High3 (21.4%)
Unknown0 (0.0%)
User Interaction
None12 (85.7%)
Unknown0 (0.0%)
Required2 (14.3%)
Privileges Required
Low1 (7.1%)
High0 (0.0%)
None13 (92.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-12997HIGH The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This ma | Jul 15, 2026 | 7.5 | 34 | NO | NO |
CVE-2025-12352CRITICAL The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and incl | Nov 7, 2025 | 9.8 | 34 | NO | NO |
CVE-2023-28782CRITICAL Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3. | Dec 20, 2023 | 9.8 | 31 | NO | NO |
CVE-2026-5111HIGH The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output | May 2, 2026 | 7.2 | 30 | NO | NO |
CVE-2026-5110HIGH The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input valida | May 2, 2026 | 7.2 | 30 | NO | NO |
CVE-2026-5109HIGH The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escapi | May 2, 2026 | 7.2 | 30 | NO | NO |
CVE-2026-5113HIGH The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.10.0. This is due to a flawed | May 2, 2026 | 7.2 | 29 | NO | NO |
CVE-2026-5112HIGH The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input valida | May 2, 2026 | 7.2 | 29 | NO | NO |
CVE-2025-12974HIGH The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechanism in all versions up to, and | Nov 18, 2025 | 8.1 | 29 | NO | NO |
CVE-2026-4394MEDIUM The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`) in all versions up to, and in | Apr 8, 2026 | 6.1 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Gravity Forms
Top CWEs
Versions
No cataloged versions.