Rocketgenius develops Gravity Forms, a widely embedded form-builder plugin for WordPress, where its vulnerability surface concentrates on web-application input handling and information exposure—specifically cross-site scripting, sensitive-data leakage, and server-side request forgery. These weakness classes are characteristic of plugin ecosystems where form processing and third-party integrations create an expanding attack surface. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rocketgenius over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13764HIGH common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) c | Jun 2, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-27852MEDIUM A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML v | Jan 20, 2021 | 5.4 | 18 | NO | NO |
CVE-2020-27851MEDIUM Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to | Jan 20, 2021 | 5.4 | 18 | NO | NO |
CVE-2020-27850MEDIUM A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML | Jan 20, 2021 | 4.8 | 18 | NO | NO |
CVE-2024-13845MEDIUM The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.0 via the 'process_feed' method of the GF_Web | May 1, 2025 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rocketgenius.
Media articles that mention a CVE ID that affects a product developed by Rocketgenius — matched by CVE ID, not by vendor name.