Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter
high
The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information...
- CVSS:
- 7.5
- Affected:
- up to 2.10.4
- Fixed in:
- 2.10.5
- Disclosed:
- Jul 15, 2026
CVE-2026-12997 on NVD →
Gravity Forms <= 2.10.0.1 - Unauthenticated Arbitrary File Deletion
critical
The Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.10.0.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the r...
- CVSS:
- 9.1
- Affected:
- up to 2.10.0.1
- Fixed in:
- 2.10.1
- Disclosed:
- Jun 1, 2026
CVE-2026-48866 on NVD →
Gravity Forms <= 2.9.30 - Unauthenticated Stored Cross-Site Scripting via Consent Field Hidden Input
high
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.9.30. This is due to a flawed state validation mechanism that fails open when input is sanitized by wp_kses(), combined with insufficient output escaping. The state valid...
- CVSS:
- 7.2
- Affected:
- up to 2.9.30
- Fixed in:
- 2.9.31
- Disclosed:
- May 1, 2026
CVE-2026-5113 on NVD →
Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Calculation Product Field in Repeater
high
The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names when rendered inside Repeater fields. The validate() method in the GF_Fi...
- CVSS:
- 7.2
- Affected:
- up to 2.10.0
- Fixed in:
- 2.10.1
- Disclosed:
- May 1, 2026
CVE-2026-5112 on NVD →
Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Product Option
high
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because the state validation function accepts submitted values where the wp_kses...
- CVSS:
- 7.2
- Affected:
- up to 2.10.0
- Fixed in:
- 2.10.1
- Disclosed:
- May 1, 2026
CVE-2026-5109 on NVD →
Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Hidden Product Field in Repeater
high
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fields, where repeater subfields bypass state validation checks and the Hi...
- CVSS:
- 7.2
- Affected:
- up to 2.10.0
- Fixed in:
- 2.10.1
- Disclosed:
- May 1, 2026
CVE-2026-5111 on NVD →
Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Single Product Field Inside Repeater
high
The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a Repeater field. When SingleProduct fields are nested within Repeater...
- CVSS:
- 7.2
- Affected:
- up to 2.10.0
- Fixed in:
- 2.10.1
- Disclosed:
- May 1, 2026
CVE-2026-5110 on NVD →
Gravity Forms <= 2.9.30 - Unauthenticated Stored Cross-Site Scripting via Credit Card 'Card Type' Sub-Field
medium
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`) in all versions up to, and including, 2.9.30. This is due to the `get_value_entry_detail()` method in the `GF_Field_CreditCard` class outputting the card type value with...
- CVSS:
- 6.1
- Affected:
- up to 2.9.30
- Fixed in:
- 2.9.31
- Disclosed:
- Apr 7, 2026
CVE-2026-4394 on NVD →
Gravity Forms <= 2.9.30 - Reflected Cross-Site Scripting via 'form_ids' Parameter
medium
The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This is due to the `GFCommon::send_json()` method outputting JSON-encoded data wrapped in HTML comment delimiters using...
- CVSS:
- 4.7
- Affected:
- up to 2.9.30
- Fixed in:
- 2.9.31
- Disclosed:
- Apr 7, 2026
CVE-2026-4406 on NVD →
Gravity Forms - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title vulnerability
medium
Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title vulnerability
- CVSS:
- 6.5
- Affected:
- up to 2.9.28
- Fixed in:
- 2.9.29
- Disclosed:
- Mar 12, 2026
Gravity Forms <= 2.9.28.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title
medium
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a compound failure involving missing authorization on the `create_from_template` AJAX endpoint (allowing any authenticated user to create forms), insufficient input sanitiza...
- CVSS:
- 6.4
- Affected:
- up to 2.9.28
- Fixed in:
- 2.9.29
- Disclosed:
- Mar 10, 2026
CVE-2026-3492 on NVD →
Gravity Forms < 2.9.29 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title
high
- Affected:
- up to 2.9.29
- Fixed in:
- 2.9.29
- Disclosed:
- Mar 10, 2026
CVE-2026-3492 on NVD →
Gravity Forms [gravityforms] < 2.9.23.1
unknown
[en] The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.
- Affected:
- up to 2.9.23.1
- Fixed in:
- 2.9.23.1
- Disclosed:
- Dec 24, 2025
CVE-2025-13407 on NVD →
Gravity Forms <= 2.9.23.0 - Unauthenticated Arbitrary File Upload
critical
The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 2.9.23.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possib...
- CVSS:
- 9.8
- Affected:
- up to 2.9.23.0
- Fixed in:
- 2.9.23.1
- Disclosed:
- Dec 3, 2025
CVE-2025-13407 on NVD →
GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload
critical
- Affected:
- up to 2.9.23.1
- Fixed in:
- 2.9.23.1
- Disclosed:
- Dec 3, 2025
CVE-2025-13407 on NVD →
Gravity Forms [gravityforms] < 2.9.22
unknown
[en] The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechanism in all versions up to, and including, 2.9.21.1. This is due to the extension blacklist not including .phar files, which can be uploaded through the chunked uploa...
- Affected:
- up to 2.9.22
- Fixed in:
- 2.9.22
- Disclosed:
- Nov 18, 2025
CVE-2025-12974 on NVD →
Gravity Forms <= 2.9.21.1 - Unauthenticated Arbitrary File Upload via Legacy Chunked Upload
high
The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechanism in all versions up to, and including, 2.9.21.1. This is due to the extension blacklist not including .phar files, which can be uploaded through the chunked upload mec...
- CVSS:
- 8.1
- Affected:
- up to 2.9.21.1
- Fixed in:
- 2.9.22
- Disclosed:
- Nov 17, 2025
CVE-2025-12974 on NVD →
Gravity Forms < 2.9.22 - Unauthenticated Arbitrary File Upload via Legacy Chunked Upload
critical
- Affected:
- up to 2.9.22
- Fixed in:
- 2.9.22
- Disclosed:
- Nov 17, 2025
CVE-2025-12974 on NVD →
Gravity Forms [gravityforms] < 2.9.21
unknown
[en] The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may m...
- Affected:
- up to 2.9.21
- Fixed in:
- 2.9.21
- Disclosed:
- Nov 7, 2025
CVE-2025-12352 on NVD →
Gravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via 'copy_post_image'
critical
The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make r...
- CVSS:
- 9.8
- Affected:
- up to 2.9.20
- Fixed in:
- 2.9.21
- Disclosed:
- Nov 6, 2025
CVE-2025-12352 on NVD →
Gravity Forms 2.9.18 - 2.9.20 - Unauthenticated Arbitrary File Upload via 'copy_post_image'
critical
- Affected:
- 2.9.18 – 2.9.21
- Fixed in:
- 2.9.21
- Disclosed:
- Nov 6, 2025
CVE-2025-12352 on NVD →
GravityForms 2.9.11.1 / 2.9.12 - Malware Compromise
unknown
- Affected:
- 2.9.11.1 – 2.9.13
- Fixed in:
- 2.9.13
- Disclosed:
- Jul 11, 2025
Gravity Forms [gravityforms] < 2.9.2
unknown
[en] The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...
- Affected:
- up to 2.9.2
- Fixed in:
- 2.9.2
- Disclosed:
- Jan 17, 2025
CVE-2024-13377 on NVD →
Gravity Forms [gravityforms] < 2.9.2
unknown
[en] The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter in versions 2.9.0.1 up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...
- Affected:
- up to 2.9.2
- Fixed in:
- 2.9.2
- Disclosed:
- Jan 17, 2025
CVE-2024-13378 on NVD →
GravityForms <= 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'alt' parameter
high
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...
- CVSS:
- 7.2
- Affected:
- up to 2.9.1.3
- Fixed in:
- 2.9.2
- Disclosed:
- Jan 16, 2025
CVE-2024-13377 on NVD →
GravityForms 2.9.0.1 - 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'style_settings' parameter
medium
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter in versions 2.9.0.1 up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- CVSS:
- 5.4
- Affected:
- 2.9.0.1 – 2.9.1.3
- Fixed in:
- 2.9.2
- Disclosed:
- Jan 16, 2025
CVE-2024-13378 on NVD →
GravityForms 2.9.0.1 - 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'style_settings' parameter
high
- Affected:
- 2.9.0.1 – 2.9.2
- Fixed in:
- 2.9.2
- Disclosed:
- Jan 16, 2025
CVE-2024-13378 on NVD →
GravityForms < 2.9.2 - Unauthenticated Stored Cross-Site Scripting via 'alt' parameter
high
- Affected:
- up to 2.9.2
- Fixed in:
- 2.9.2
- Disclosed:
- Jan 16, 2025
CVE-2024-13377 on NVD →
Gravity Forms [gravityforms] < 2.7.4
unknown
[en] Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.4
- Disclosed:
- Dec 20, 2023
CVE-2023-28782 on NVD →
Gravity Forms [gravityforms] < 2.0.7
unknown
Update the plugin.
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gravity Forms Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests v...
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Oct 13, 2023
Gravity Forms [gravityforms] < 2.7.5
unknown
[en] The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Jul 17, 2023
CVE-2023-2701 on NVD →
Gravity Forms <= 2.7.4 - Reflected Cross-Site Scripting
medium
The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.5
- Disclosed:
- Jun 21, 2023
CVE-2023-2701 on NVD →
Gravity Forms < 2.7.5 - Reflected XSS
medium
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Jun 21, 2023
CVE-2023-2701 on NVD →
Gravity Forms [gravityforms] < 1.8.20
unknown
Upgrade the plugin.
Abk Khan discovered and reported this Local File Inclusion vulnerability in WordPress Gravity Forms Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potenti...
- Affected:
- up to 1.8.20
- Fixed in:
- 1.8.20
- Disclosed:
- Jun 17, 2023
Gravity Forms <= 2.7.3 - Unauthenticated PHP Object Injection
critical
The Gravity Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.7.3 via deserialization of untrusted input in the get_field_input function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is p...
- CVSS:
- 9.8
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.4
- Disclosed:
- May 29, 2023
CVE-2023-28782 on NVD →
Gravity Forms < 2.7.4 - Unauthenticated PHP Object Injection
critical
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.4
- Disclosed:
- May 29, 2023
CVE-2023-28782 on NVD →
Gravity Forms [gravityforms] < 1.9.7
unknown
Update the plugin to the latest version.
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gravity Forms Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be...
- Affected:
- up to 1.9.7
- Fixed in:
- 1.9.7
- Disclosed:
- Apr 20, 2023
Gravity Forms [gravityforms] < 1.9.3.6
unknown
Update the plugin.
An unknown person discovered and reported this SQL Injection vulnerability in WordPress Gravity Forms Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 1.9.3.6.
- Affected:
- up to 1.9.3.6
- Fixed in:
- 1.9.3.6
- Disclosed:
- Mar 17, 2023
Gravity Forms [gravityforms] < 1.9.16
unknown
Update the plugin.
Henri Salo discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gravity Forms Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit yo...
- Affected:
- up to 1.9.16
- Fixed in:
- 1.9.16
- Disclosed:
- Mar 1, 2023
Gravity Forms [gravityforms] < 2.4.9
unknown
[en] common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.
- Affected:
- up to 2.4.9
- Fixed in:
- 2.4.9
- Disclosed:
- Jun 2, 2020
CVE-2020-13764 on NVD →
Gravityforms <= 2.4.8 - Information Exposure
high
common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.
- CVSS:
- 7.5
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.9
- Disclosed:
- May 8, 2019
CVE-2020-13764 on NVD →
GravityForms < 2.4.9 - Hashed Password Leakage
unknown
- Affected:
- up to 2.4.9
- Fixed in:
- 2.4.9
- Disclosed:
- May 8, 2019
CVE-2020-13764 on NVD →
Gravity Forms < 2.0.7 - Authenticated Blind Cross-Site Scripting (XSS)
medium
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Oct 13, 2016
Gravity Forms <= 2.0.6.5 - Cross-Site Scripting
medium
WordPress Plugin Gravity Forms is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal...
- CVSS:
- 5.4
- Affected:
- up to 2.0.6.5
- Fixed in:
- 2.0.7
- Disclosed:
- Sep 7, 2016
Gravity Forms [gravityforms] < 2.0.7
unknown
WordPress Plugin Gravity Forms is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal...
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Sep 7, 2016
Gravityforms <= 1.9.15.11 - Cross-Site Scripting
medium
The Gravityforms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting up to, and including, 1.9.15.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a us...
- CVSS:
- 4.7
- Affected:
- up to 1.9.15.11
- Fixed in:
- 1.9.16
- Disclosed:
- Mar 1, 2016
Gravity Forms < 1.9.16 - Authenticated Reflected Cross-Site Scripting (XSS)
medium
- Affected:
- up to 1.9.16
- Fixed in:
- 1.9.16
- Disclosed:
- Mar 1, 2016
Gravity Forms [gravityforms] < 1.9.16
unknown
The Gravityforms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting up to, and including, 1.9.15.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a us...
- Affected:
- up to 1.9.16
- Fixed in:
- 1.9.16
- Disclosed:
- Mar 1, 2016
Gravityforms <= 1.9.6 - Cross-Site Scripting
medium
The Gravityforms plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.6 due to insufficient input sanitization and output escaping alongside the use of add_query_arg or remove_query_arg(). This makes it possible for attackers to inject arbitrary web scripts that execute in a...
- CVSS:
- 5.4
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.7
- Disclosed:
- Apr 20, 2015
Gravity Forms <= 1.9.6 - Cross-Site Scripting (XSS)
medium
- Affected:
- up to 1.9.7
- Fixed in:
- 1.9.7
- Disclosed:
- Apr 20, 2015
Gravity Forms [gravityforms] < 1.9.7
unknown
The Gravityforms plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.6 due to insufficient input sanitization and output escaping alongside the use of add_query_arg or remove_query_arg(). This makes it possible for attackers to inject arbitrary web scripts that execute in a...
- Affected:
- up to 1.9.7
- Fixed in:
- 1.9.7
- Disclosed:
- Apr 20, 2015
Gravityforms <= 1.9.3.5 - SQL Injection
critical
The Gravifyforms plugin for WordPress is vulnerable to blind SQL Injection via the ‘sort_column GET’ parameter in versions up to, and including,1.9.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...
- CVSS:
- 9.1
- Affected:
- up to 1.9.3.5
- Fixed in:
- 1.9.3.6
- Disclosed:
- Mar 17, 2015
CVE-2015-2260 on NVD →
Gravity Forms 1.8 <= 1.9.3.5 - Authenticated Blind SQL Injection
critical
- Affected:
- up to 1.9.3.6
- Fixed in:
- 1.9.3.6
- Disclosed:
- Mar 17, 2015
Gravityforms <= 1.8.19 - Arbitrary File Upload
critical
The Gravityforms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the includes/upload.php file in versions up to, and including, 1.8.19. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote c...
- CVSS:
- 9.8
- Affected:
- up to 1.8.20
- Fixed in:
- 1.8.20
- Disclosed:
- Feb 26, 2015
Gravity Forms [gravityforms] < 1.8.20
unknown
The Gravityforms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the includes/upload.php file in versions up to, and including, 1.8.19. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote c...
- Affected:
- up to 1.8.20
- Fixed in:
- 1.8.20
- Disclosed:
- Feb 26, 2015
Gravity Forms <= 1.8.19 - Arbitrary File Upload
critical
- Affected:
- up to 1.8.20
- Fixed in:
- 1.8.20
- Disclosed:
- Dec 8, 2014
Gravity Forms [gravityforms] >= 1.8 - <= 1.9.3.5
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- 1.8 – 1.9.3.5
- Fixed in:
- 1.9.3.5
CVE-2015-2260 on NVD →
Gravity Forms [gravityforms] < 1.8.20
unknown
The gravityforms WordPress plugin was affected by an Arbitrary File Upload security vulnerability.
- Affected:
- up to 1.8.20
- Fixed in:
- 1.8.20
Gravity Forms [gravityforms] < 1.9.3.6
unknown
Title: Gravity Forms 1.8 <= 1.9.3.5 - Blind SQL Injection CVE-2015-2260
Version/s Tested: 1.9.3.1
Description:
Gravity Forms is one of the most popular WordPress plugins (gravityforms) used to create forms for WordPress sites. The latest version at the time of writing (1.9.3.5) contains an authenticated (admi...
- Affected:
- up to 1.9.3.6
- Fixed in:
- 1.9.3.6
Gravity Forms [gravityforms] < 1.9.7
unknown
The gravityforms WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.9.7
- Fixed in:
- 1.9.7
Gravity Forms [gravityforms] < 1.9.16
unknown
The gravityforms WordPress plugin was affected by a Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.9.16
- Fixed in:
- 1.9.16
Gravity Forms [gravityforms] < 2.0.7
unknown
A blind XSS vulnerability exists in the GravityForms plugin prior to version 2.0.7, in the select option dropdown boxes on forms. If the select column is displayed on the gf_entries page when viewed in the Dashboard, the code is executed by the admin / viewer of the submissions.
This vulnerability was responsibly di...
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7