Infinitumform's vulnerability footprint centers on its Geo Controller product, a narrowly scoped infrastructure component with a durable signal around access-control and deserialization weaknesses. These weakness classes—missing authorization and untrusted deserialization—reflect the authentication and data-handling demands of a geolocation control system. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infinitumform over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-62109HIGH Insertion of Sensitive Information Into Sent Data vulnerability in INFINITUM FORM Geo Controller cf-geoplugin allows Retrieve Embedded Sensitive Data.This issue affects Geo Control | Dec 9, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-30227CRITICAL Deserialization of Untrusted Data vulnerability in INFINITUM FORM Geo Controller.This issue affects Geo Controller: from n/a through 8.6.4. | Mar 28, 2024 | 9.0 | 23 | NO | NO |
CVE-2024-30451MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in INFINITUM FORM Geo Controller allows Stored XSS.This issue affects Geo Control | Mar 29, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-3591MEDIUM The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthenticated users to perform PHP Ob | May 1, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-7381MEDIUM The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function i | Sep 5, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-7380MEDIUM The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability checks on the ajax__geolocate_menu and ajax__geolocate_remove | Sep 5, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infinitumform.
Media articles that mention a CVE ID that affects a product developed by Infinitumform — matched by CVE ID, not by vendor name.