Incsub
Incsub Forminator: vulnerabilidades y CVE
Incsub Forminator tiene 41 vulnerabilidades publicadas, 20 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE41
Últimos 12 meses20
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-92144 | Alta (7.2) | — | — | 1 oct 2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in all versions up to, and including,… |
| CVE-2026-85235 | Alta (7.2) | — | — | 1 oct 2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.2 due to… |
| CVE-2026-87071 | Media (5.3) | 0.19% | — | 23 sept 2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress reserves for its own use, so unauthenticated visitors… |
| CVE-2026-87069 | Baja (3.1) | 0.13% | — | 23 sept 2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and… |
| CVE-2026-87068 | Media (6.6) | 0.36% | — | 20 sept 2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to… |
| CVE-2026-92229 | Crítica (9.1) | 0.73% | — | 19 sept 2026 | The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software… |
| CVE-2026-82220 | Media (5.3) | 0.29% | — | 28 ago 2026 | Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions. |
| CVE-2026-18324 | Alta (7.2) | 0.45% | — | 28 ago 2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due… |
| CVE-2026-19220 | Baja (3.7) | 0.15% | — | 26 ago 2026 | The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress… |
| CVE-2026-19221 | Alta (7.2) | 0.66% | — | 22 ago 2026 | The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code… |
| CVE-2026-66583 | Crítica (9.8) | 0.56% | — | 20 ago 2026 | Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. |
| CVE-2026-15748 | Crítica (9.8) | 6.1% | — | 18 ago 2026 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in… |
| CVE-2026-28143 | Alta (7.1) | 0.25% | — | 6 ago 2026 | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. |
| CVE-2026-28111 | Alta (8.8) | 0.42% | — | 6 ago 2026 | Contributor Privilege Escalation in Forminator <= 1.56.0 versions. |
| CVE-2026-56071 | Alta (7.1) | 0.25% | — | 25 jun 2026 | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions. |
| CVE-2026-6214 | Media (6.5) | 0.45% | — | 7 may 2026 | The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_for_saving_export_schedule() function in library/class-export.php… |
| CVE-2026-6222 | Media (5.3) | 0.42% | — | 7 may 2026 | The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method in `Forminator_Admin_Module_Edit_Page`… |
| CVE-2026-2729 | Media (5.3) | 0.35% | — | 5 may 2026 | The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. This is due to the plugin not properly verifying that a user is authorized to perform an action… |
| CVE-2026-2002 | Media (4.4) | 0.17% | — | 17 feb 2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form_name parameter in all versions up to, and including, 1.50.2 due to… |
| CVE-2025-14782 | Media (5.3) | 0.29% | — | 9 ene 2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.49.1 via the 'listen_for_csv_export' function.… |
| CVE-2025-7638 | Media (4.9) | 0.29% | — | 18 jul 2025 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and including, 1.45.0 due to… |
| CVE-2025-6464 | Alta (8.8) | 0.53% | — | 2 jul 2025 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via deserialization of untrusted input in… |
| CVE-2025-6463 | Alta (8.8) | 13% | — | 2 jul 2025 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'entry_delete_upload_files' function… |
| CVE-2024-45625 | Media (6.1) | 0.43% | — | 9 sept 2024 | Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows a crafted URL and… |
| CVE-2024-7389 | Alta (7.5) | 0.66% | — | 2 ago 2024 | The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated… |
| CVE-2024-31857 | Media (5.4) | 0.63% | — | 23 abr 2024 | Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain user information etc. and alter the page contents on the user's web browser. |
| CVE-2024-31077 | Alta (7.2) | 30% | — | 23 abr 2024 | Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain and alter any information in the… |
| CVE-2024-28890 | Media (5.3) | 0.71% | — | 23 abr 2024 | Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by accessing files on the… |
| CVE-2024-3053 | Media (5.4) | 0.36% | — | 9 abr 2024 | The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ forminator_form shortcode attribute in versions up to, and including,… |
| CVE-2024-1794 | Media (6.1) | 0.53% | — | 9 abr 2024 | The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) in all versions up to, and including, 1.29.0 due to insufficient input sanitization and output… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.