Mondula develops a web form builder product whose vulnerability profile skews toward serious outcomes, with a meaningful share reaching critical severity. The exposure centers on the Multi-Step Form product and recurs through web-layer weakness classes including cross-site scripting, cross-site request forgery, and missing authorization, which are characteristic of user-facing form and data-handling systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mondula over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-50428CRITICAL Missing Authorization vulnerability in mondula2016 Multi Step Form multi-step-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Multi | Oct 29, 2024 | 9.8 | 34 | NO | NO |
CVE-2023-47758HIGH Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form plugin <= 1.7.11 versions. | Nov 22, 2023 | 8.8 | 25 | NO | NO |
CVE-2018-14430MEDIUM The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_data [id][3], fw_data [id][4], or email field of the contact | Jul 25, 2018 | 6.1 | 21 | NO | NO |
CVE-2022-4196MEDIUM The Multi Step Form WordPress plugin before 1.7.8 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Stored Cross | Jan 9, 2023 | 4.8 | 19 | NO | NO |
CVE-2018-14846MEDIUM The Mondula Multi Step Form plugin before 1.2.8 for WordPress has multiple stored XSS via wp-admin/admin-ajax.php. | Dec 20, 2018 | 5.4 | 19 | NO | NO |
CVE-2024-12427MEDIUM The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to | Jan 16, 2025 | 5.3 | 16 | NO | NO |
CVE-2024-25905MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from n/a through 1.7.18. | Feb 21, 2024 | 5.4 | 16 | NO | NO |
CVE-2023-50832MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mondula GmbH Multi Step Form allows Stored XSS.This issue affects Multi Step F | Dec 21, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mondula.
Media articles that mention a CVE ID that affects a product developed by Mondula — matched by CVE ID, not by vendor name.