« Volver al listado

Incsub

Incsub Forminator: vulnerabilidades y CVE

Incsub Forminator tiene 41 vulnerabilidades publicadas, 20 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE41
Últimos 12 meses20
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-92144Alta (7.2)——1 oct 2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in all versions up to, and including,…
CVE-2026-85235Alta (7.2)——1 oct 2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.2 due to…
CVE-2026-87071Media (5.3)0.19%—23 sept 2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress reserves for its own use, so unauthenticated visitors…
CVE-2026-87069Baja (3.1)0.13%—23 sept 2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and…
CVE-2026-87068Media (6.6)0.36%—20 sept 2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to…
CVE-2026-92229Crítica (9.1)0.73%—19 sept 2026
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software…
CVE-2026-82220Media (5.3)0.29%—28 ago 2026
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
CVE-2026-18324Alta (7.2)0.45%—28 ago 2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due…
CVE-2026-19220Baja (3.7)0.15%—26 ago 2026
The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress…
CVE-2026-19221Alta (7.2)0.66%—22 ago 2026
The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code…
CVE-2026-66583Crítica (9.8)0.56%—20 ago 2026
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
CVE-2026-15748Crítica (9.8)6.1%—18 ago 2026
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in…
CVE-2026-28143Alta (7.1)0.25%—6 ago 2026
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
CVE-2026-28111Alta (8.8)0.42%—6 ago 2026
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
CVE-2026-56071Alta (7.1)0.25%—25 jun 2026
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.
CVE-2026-6214Media (6.5)0.45%—7 may 2026
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_for_saving_export_schedule() function in library/class-export.php…
CVE-2026-6222Media (5.3)0.42%—7 may 2026
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method in `Forminator_Admin_Module_Edit_Page`…
CVE-2026-2729Media (5.3)0.35%—5 may 2026
The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. This is due to the plugin not properly verifying that a user is authorized to perform an action…
CVE-2026-2002Media (4.4)0.17%—17 feb 2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form_name parameter in all versions up to, and including, 1.50.2 due to…
CVE-2025-14782Media (5.3)0.29%—9 ene 2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.49.1 via the 'listen_for_csv_export' function.…
CVE-2025-7638Media (4.9)0.29%—18 jul 2025
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and including, 1.45.0 due to…
CVE-2025-6464Alta (8.8)0.53%—2 jul 2025
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via deserialization of untrusted input in…
CVE-2025-6463Alta (8.8)13%—2 jul 2025
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'entry_delete_upload_files' function…
CVE-2024-45625Media (6.1)0.43%—9 sept 2024
Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows a crafted URL and…
CVE-2024-7389Alta (7.5)0.66%—2 ago 2024
The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated…
CVE-2024-31857Media (5.4)0.63%—23 abr 2024
Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain user information etc. and alter the page contents on the user's web browser.
CVE-2024-31077Alta (7.2)30%—23 abr 2024
Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain and alter any information in the…
CVE-2024-28890Media (5.3)0.71%—23 abr 2024
Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by accessing files on the…
CVE-2024-3053Media (5.4)0.36%—9 abr 2024
The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ forminator_form shortcode attribute in versions up to, and including,…
CVE-2024-1794Media (6.1)0.53%—9 abr 2024
The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) in all versions up to, and including, 1.29.0 due to insufficient input sanitization and output…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application3
  2. T1059.007 JavaScript2
  3. T1210 Exploitation of Remote Services2
  4. T1565.001 Stored Data Manipulation2
  5. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Incsub