Piotnet develops WordPress-oriented form and plugin products whose vulnerabilities cluster around web-application input handling, specifically unrestricted file uploads and cross-site scripting flaws. These weakness classes are typical of extensible WordPress ecosystems where user-supplied content flows through page generation and file-storage pipelines; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Piotnet over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4883CRITICAL The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions u | May 19, 2026 | 9.8 | 36 | NO | NO |
CVE-2023-6220CRITICAL The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'piotnetforms_ajax_form_builder' function in versions | Jan 11, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-51412CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in Piotnet Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.25. | Dec 29, 2023 | 9.8 | 26 | NO | NO |
CVE-2024-5502MEDIUM The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion, Dual Heading, and Vertical Timeline widgets in | Aug 23, 2024 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Piotnet.
Media articles that mention a CVE ID that affects a product developed by Piotnet — matched by CVE ID, not by vendor name.