Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Gravity Forms — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Gravity Forms, with AI-generated Chinese analysis, references, and POCs.

This page details security vulnerabilities affecting Gravity Forms, a popular WordPress plugin for creating forms. It aggregates reports from major security databases and vendor advisories covering the period from 2016 through the present day. These entries document a variety of weaknesses, including cross-site scripting, path traversal, and improper access control issues that were identified in the plugin’s codebase. The collection serves as a centralized reference for developers, security analysts, and site administrators who need to assess the risk posture of this specific tool. By reviewing this curated data, users can effectively track a vendor's advisory history to understand how issues were reported and patched over time. It also allows for a deeper understanding of specific weakness classes prevalent in WordPress plugins, providing context on how such flaws are typically exploited. Furthermore, individuals can look up a product's vulnerability history to identify recurring problem areas or persistent bugs that may indicate underlying architectural weaknesses. This historical perspective is crucial for making informed decisions about plugin maintenance and security auditing. The data presented here is structured to facilitate efficient searching and comparison, enabling stakeholders to quickly locate relevant information without sifting through unrelated noise. Ultimately, this resource aims to improve transparency and security awareness within the WordPress ecosystem by providing clear, accessible information about known defects in widely used software.

Vendor: Rocketgenius Inc.

CVE IDTitleCVSSSeverityPublished
CVE-2026-12997 Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter CWE-22 7.5 High2026-07-15
CVE-2026-48866 WordPress Gravity Forms plugin <= 2.10.0.1 - Arbitrary File Deletion vulnerability CWE-22 9.6 Critical2026-06-01
CVE-2026-5110 Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Single Product Field Inside Repeater CWE-79 7.2 High2026-05-02
CVE-2026-5111 Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Hidden Product Field in Repeater CWE-79 7.2 High2026-05-02
CVE-2026-5112 Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Calculation Product Field in Repeater CWE-79 7.2 High2026-05-02
CVE-2026-5109 Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Product Option CWE-79 7.2 High2026-05-02
CVE-2026-5113 Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Consent Field Hidden Input CWE-79 7.2 High2026-05-02
CVE-2026-4406 Gravity Forms <= 2.9.30 - Reflected Cross-Site Scripting via 'form_ids' Parameter CWE-79 4.7 Medium2026-04-07
CVE-2026-4394 Gravity Forms <= 2.9.30 - Unauthenticated Stored Cross-Site Scripting via Credit Card 'Card Type' Sub-Field CWE-79 6.1 Medium2026-04-07
CVE-2026-3492 Gravity Forms <= 2.9.28.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title CWE-79 6.4 Medium2026-03-11
CVE-2025-13407 GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload 9.8AICriticalAI2025-12-24
CVE-2025-12974 Gravity Forms <= 2.9.21.1 - Unauthenticated Arbitrary File Upload via Legacy Chunked Upload CWE-434 8.1 High2025-11-18
CVE-2025-12352 Gravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via 'copy_post_image' CWE-434 9.8 Critical2025-11-07
CVE-2024-13378 GravityForms 2.9.0.1 - 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'style_settings' parameter CWE-79 5.4 Medium2025-01-17
CVE-2024-13377 GravityForms <= 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'alt' parameter CWE-79 7.2 High2025-01-17
CVE-2023-28782 WordPress Gravity Forms Plugin <= 2.7.3 is vulnerable to PHP Object Injection CWE-502 8.3 High2023-12-20

All 16 known CVE vulnerabilities affecting Gravity Forms with full Chinese analysis, references, and POCs where available.