Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Incsub

First CVE: Mar 4, 2019Active for: 7 yearsTotal CVEs: 28
34.9
VTI Score
Medium

Incsub develops a focused portfolio of WordPress plugins and themes that serve community-building, lead-generation, and performance-optimization functions, positioning the vendor in a large ecosystem of widely deployed web applications. The vendor's vulnerability footprint clusters around web application and plugin-specific weakness classes—notably cross-site scripting, unrestricted file uploads, cross-site request forgery, path traversal, and SQL injection—reflecting the input-handling and access-control demands of user-facing WordPress extensions. A meaningful share of these vulnerabilities reach serious severity outcomes, driven by the attack surface that web-facing forms, content uploads, and database queries present. Defenders should track this vendor's plugin updates closely and treat remediation of affected installations as routine given the breadth of WordPress deployment. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Incsub over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 4, 2019
7 years ago
Most Recent CVE
Jun 25, 2026
29 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-4596CRITICAL
The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_im
Aug 30, 20239.840NOYES
CVE-2024-31077HIGH
Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain a
Apr 23, 20247.237NONO
CVE-2025-6463HIGH
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in th
Jul 2, 20258.832NONO
CVE-2026-56071HIGH
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.
Jun 25, 20267.131NONO
CVE-2023-1478CRITICAL
The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the p
Apr 10, 20239.829NONO
CVE-2019-11872HIGH
The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation g
May 29, 20198.828NONO
CVE-2025-6464HIGH
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via
Jul 2, 20258.825NONO
CVE-2024-43118HIGH
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.9.1.
Nov 1, 20248.823NONO
CVE-2019-9568MEDIUM
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the att
Mar 4, 20196.523NONO
CVE-2024-7389HIGH
The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This
Aug 2, 20247.522NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
61%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (3.6%)
Network27 (96.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (96.4%)
High1 (3.6%)
Unknown0 (0.0%)
User Interaction
None11 (39.3%)
Unknown0 (0.0%)
Required17 (60.7%)
Privileges Required
Low5 (17.9%)
High5 (17.9%)
None18 (64.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.6% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Incsub.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Incsub — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Incsub's Products

View all 5 CNAs →

Top CWEs