Kaliforms' vulnerability profile centers on a pair of web-based form-building and contact-management products that serve small-to-medium deployment contexts. The recurring exposure is marked by authorization and access-control weaknesses—including missing authorization checks, authorization bypass via user-controlled keys, and CSRF—alongside input-handling issues such as cross-site scripting, reflecting the challenges of validating and controlling user interactions in form-processing applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kaliforms over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36717HIGH The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plug | Jun 7, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-22305HIGH Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder | Jan 31, 2024 | 8.1 | 23 | NO | NO |
CVE-2020-36720HIGH The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentic | Jun 7, 2023 | 7.1 | 21 | NO | NO |
CVE-2024-1218MEDIUM The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsiste | Feb 29, 2024 | 5.4 | 18 | NO | NO |
CVE-2020-36712MEDIUM The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploa | Jun 7, 2023 | 5.3 | 18 | NO | NO |
CVE-2025-3201MEDIUM The Contact Form builder with drag & drop for WordPress WordPress plugin before 2.4.3 does not sanitise and escape some of its settings, which could allow high privilege users suc | May 16, 2025 | 5.9 | 17 | NO | NO |
CVE-2024-1217MEDIUM The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the | Feb 29, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kaliforms.
Media articles that mention a CVE ID that affects a product developed by Kaliforms — matched by CVE ID, not by vendor name.