Infusionsoft Gravity Forms Project develops a form-building plugin with a narrowly scoped product portfolio centered on its Gravity Forms component. The observed vulnerability signal is concentrated in code-injection weaknesses, reflecting the dynamic nature of form handling and template processing in WordPress-based form systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infusionsoft Gravity Forms Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6446HIGH The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbi | Sep 26, 2014 | 7.5 | 69 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infusionsoft Gravity Forms Project.
Media articles that mention a CVE ID that affects a product developed by Infusionsoft Gravity Forms Project — matched by CVE ID, not by vendor name.