Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gravityforms gravity forms vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-28782
Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a up to and including 2.7.3.
Gravityforms Gravity Forms
6.5
CVSSv3
CVE-2023-2326
The Gravity Forms Google Sheet Connector WordPress plugin prior to 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin up to and including 1.3.5 does not have CSRF check when updating its Access Code, which could allow malicious users to make logged in admin change the acces...
Gsheetconnector Gravity Forms Google Sheets Connector
4.8
CVSSv3
CVE-2020-27850
A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms prior to 2.4.21 allows remote malicious users to inject arbitrary web script or HTML via the import of a GF form. This code is interpreted by users in a privileged role (Admini...
Rocketgenius Gravityforms
7.5
CVSSv3
CVE-2020-13764
common.php in the Gravity Forms plugin prior to 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.
Rocketgenius Gravityforms
5.4
CVSSv3
CVE-2020-27852
A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms prior to 2.4.21 allows remote malicious users to inject arbitrary web script or HTML via a textarea field. This code is interpreted by users in a privileged role (Administrator, ...
Rocketgenius Gravityforms
5.4
CVSSv3
CVE-2020-27851
Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms prior to 2.4.21 allows remote malicious users to inject arbitrary HTML code via poll or quiz answers. This code is inter...
Rocketgenius Gravityforms
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started