Forminator
Vendor:
First CVE: Mar 4, 2019 · Active for 7 years
21
Total CVEs
More Total CVEs than 94% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Forminator over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 4, 2019
7 years ago
Most Recent CVE
Jun 25, 2026
28 days ago
CVE Severity & Scoring
Forminator21 CVEs
67%
24%
All CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (4.8%)
Network20 (95.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (95.2%)
High1 (4.8%)
Unknown0 (0.0%)
User Interaction
None7 (33.3%)
Unknown0 (0.0%)
Required14 (66.7%)
Privileges Required
Low4 (19.0%)
High4 (19.0%)
None13 (61.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4596CRITICAL The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_im | Aug 30, 2023 | 9.8 | 40 | NO | YES |
CVE-2024-31077HIGH Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain a | Apr 23, 2024 | 7.2 | 37 | NO | NO |
CVE-2025-6463HIGH The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in th | Jul 2, 2025 | 8.8 | 32 | NO | NO |
CVE-2026-56071HIGH Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions. | Jun 25, 2026 | 7.1 | 31 | NO | NO |
CVE-2025-6464HIGH The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via | Jul 2, 2025 | 8.8 | 25 | NO | NO |
CVE-2019-9568MEDIUM The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the att | Mar 4, 2019 | 6.5 | 23 | NO | NO |
CVE-2024-7389HIGH The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This | Aug 2, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-3134MEDIUM The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form fields that use pre-populated query parameters, which could lead | Jul 31, 2023 | 6.1 | 21 | NO | NO |
CVE-2021-36821MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Stored XSS.This issue affects Forminator: fr | Mar 16, 2023 | 6.1 | 21 | NO | NO |
CVE-2024-28890MEDIUM Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive inf | Apr 23, 2024 | 5.3 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.8% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Forminator
Top CWEs
Versions
No cataloged versions.