Tripetto is a web-based form and survey platform whose vulnerability profile concentrates on application-layer input handling, with observed weaknesses centered on cross-site scripting variants and cross-site request forgery that are characteristic of interactive web applications. Treat this as a compact, focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tripetto over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36895MEDIUM Unauthenticated Cross-Site Scripting (XSS) vulnerability in Tripetto's Tripetto plugin <= 5.1.4 on WordPress via SVG image upload. | Apr 26, 2022 | 6.1 | 22 | NO | NO |
CVE-2024-13497MEDIUM The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via attachment uploads in all | Mar 15, 2025 | 6.1 | 20 | NO | NO |
CVE-2024-10260MEDIUM The Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, and including, 8.0.11 due to insufficient input sanitization | Nov 15, 2024 | 6.1 | 19 | NO | NO |
CVE-2025-1530MEDIUM The Tripetto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.9. This is due to missing nonce validation. This makes it po | Mar 15, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tripetto.
Media articles that mention a CVE ID that affects a product developed by Tripetto — matched by CVE ID, not by vendor name.