Jumpdemand's vulnerability footprint concentrates in web-based forms and demand-generation products, with the recurring signal centered on authentication and input-handling weaknesses including improper authentication controls and cross-site scripting in web page generation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jumpdemand over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-22504CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in jumpdemand 4ECPS Web Forms 4ecps-webforms allows Upload a Web Shell to a Web Server.This issue affects 4ECPS Web Fo | Jan 9, 2025 | 10.0 | 30 | NO | NO |
CVE-2022-36296MEDIUM Broken Authentication vulnerability in JumpDEMAND Inc. ActiveDEMAND plugin <= 0.2.27 at WordPress allows unauthenticated post update/create/delete. | Aug 5, 2022 | 5.3 | 20 | NO | NO |
CVE-2022-44628MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JumpDEMAND Inc. 4ECPS Web Forms plugin <= 0.2.17 on WordPress. | Nov 3, 2022 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jumpdemand.
Media articles that mention a CVE ID that affects a product developed by Jumpdemand — matched by CVE ID, not by vendor name.