Forminator

Vendor:

First CVE: Mar 4, 2019 · Active for 7 years

21
Total CVEs
More Total CVEs than 94% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Forminator over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 4, 2019
7 years ago
Most Recent CVE
Jun 25, 2026
28 days ago

CVE Severity & Scoring

Forminator21 CVEs
All CVEs352,101 CVEs
LowMediumHighCritical
Attack Vector
Local1 (4.8%)
Network20 (95.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (95.2%)
High1 (4.8%)
Unknown0 (0.0%)
User Interaction
None7 (33.3%)
Unknown0 (0.0%)
Required14 (66.7%)
Privileges Required
Low4 (19.0%)
High4 (19.0%)
None13 (61.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_im
Aug 30, 20239.840NOYES
Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain a
Apr 23, 20247.237NONO
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in th
Jul 2, 20258.832NONO
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.
Jun 25, 20267.131NONO
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via
Jul 2, 20258.825NONO
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the att
Mar 4, 20196.523NONO
The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This
Aug 2, 20247.522NONO
The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form fields that use pre-populated query parameters, which could lead
Jul 31, 20236.121NONO
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Stored XSS.This issue affects Forminator: fr
Mar 16, 20236.121NONO
Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive inf
Apr 23, 20245.320NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.8% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Forminator

Top CWEs

Versions

No cataloged versions.