Happyforms is a form-builder plugin that achieves notable adoption relative to its narrow scope, with its vulnerability exposure centered on the single product and recurrent issues in input sanitization and authorization controls. These weakness patterns—cross-site scripting through improper neutralization of user-supplied data and missing authorization checks—are characteristic of web-facing form handling and reflect the surface area of a publicly accessible data-collection tool. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Happyforms over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-49768CRITICAL Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. | Jun 15, 2026 | 9.8 | 35 | NO | NO |
CVE-2023-48752MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Happyforms Form builder to get in touch with visitors, grow your email list an | Nov 30, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-0096MEDIUM The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which coul | Feb 6, 2023 | 5.4 | 18 | NO | NO |
CVE-2024-44063MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Happyforms allows Stored XSS.This issue affects Happyforms: from n/a th | Sep 15, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-23521MEDIUM Missing Authorization vulnerability in Happyforms.This issue affects Happyforms: from n/a through 1.25.10. | Jun 11, 2024 | 5.3 | 16 | NO | NO |
CVE-2024-10054MEDIUM The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site | May 15, 2025 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Happyforms.
Media articles that mention a CVE ID that affects a product developed by Happyforms — matched by CVE ID, not by vendor name.