Ncrafts develops FormCraft, a web form builder product that sits prominently in the WordPress plugin ecosystem. Its disclosures center on application-layer input-handling and authorization weaknesses—cross-site scripting, SQL injection, CSRF, and missing authorization controls—that are typical of plugins processing user-supplied form data. Public exploit code has frequently been made available for vulnerabilities in this product, and live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ncrafts over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7187HIGH SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. | Dec 20, 2013 | 7.5 | 34 | NO | YES |
CVE-2019-15114HIGH The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF. | Aug 16, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-5920HIGH Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page. | Mar 12, 2019 | 8.8 | 26 | NO | NO |
CVE-2023-2592HIGH The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high pri | Jun 27, 2023 | 7.2 | 22 | NO | NO |
CVE-2023-22717MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in nCrafts FormCraft plugin <= 1.2.6 versions. | May 15, 2023 | 5.4 | 20 | NO | NO |
CVE-2017-18600MEDIUM The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field. | Sep 10, 2019 | 5.4 | 20 | NO | NO |
CVE-2025-0817MEDIUM The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.9.11 due to insufficient input sanitiza | Feb 18, 2025 | 6.1 | 19 | NO | NO |
CVE-2022-1647MEDIUM The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when | Jun 8, 2022 | 4.8 | 16 | NO | NO |
CVE-2024-13783MEDIUM The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in formcraft-main.php in all versions up to, and including, 3.9.11 | Feb 18, 2025 | 4.3 | 15 | NO | NO |
CVE-2023-47823MEDIUM Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2. | Dec 9, 2024 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ncrafts.
Media articles that mention a CVE ID that affects a product developed by Ncrafts — matched by CVE ID, not by vendor name.