{"error":0,"message":null,"data":{"name":"Gravity Forms","plugin":"gravityforms","link":"https:\/\/www.gravityforms.com\/","latest":null,"closed":null,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"b7e407bdd277bf36ef4f97b005bfffb0a9b24f184bff90bf6b38856b0cf06ff2","name":"Gravity Forms [gravityforms] < 2.4.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-13764","name":"CVE-2020-13764","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-13764","description":"[en] common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.","date":"2020-06-02"},{"id":"6157c5b52b5910c838318731aeada3ecf7824335","name":"Gravityforms <= 2.4.8 - Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravityforms-248-information-exposure","description":"common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.","date":"2019-05-08"},{"id":"09a9ced9-ff06-42e3-964f-c51230a95e32","name":"GravityForms &lt; 2.4.9 - Hashed Password Leakage","link":"https:\/\/wpscan.com\/vulnerability\/09a9ced9-ff06-42e3-964f-c51230a95e32","description":"The gravityforms WordPress plugin was affected by a Hashed Password Leakage security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}]}},{"uuid":"de210e119481952b31867c86625aa2790b31263e6ef07978ad328ea5c2344a82","name":"Gravity Forms [gravityforms] < 2.0.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f5d87f3ca0c88b68787e2a10f61768b74394806a","name":"Gravity Forms <= 2.0.6.5 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-2065-cross-site-scripting","description":"WordPress Plugin Gravity Forms is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. WordPress Plugin Gravity Forms version 2.0.6.5 is vulnerable; prior versions may also be affected.","date":"2016-09-07"}],"impact":[]},{"uuid":"7a2f8a7625394eea6a6c782e948fa290d1183a3eb514ac6148f0dbcbeaa29341","name":"Gravity Forms [gravityforms] < 1.9.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"64277fd01f04c0a41ea4d9ecfcd75cb847bd1a5e","name":"Gravityforms <= 1.9.15.11 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravityforms-191511-cross-site-scripting","description":"The Gravityforms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting up to, and including, 1.9.15.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2016-03-01"}],"impact":[]},{"uuid":"2530f07870a9e3d067b3425e414a3b6d9ec454d9a2f4a11e8fe69c8ef97dd392","name":"Gravity Forms [gravityforms] < 1.9.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a9bdf699fac327123e828b3d3b1e712889fe67ed","name":"Gravityforms <= 1.9.6 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravityforms-196-cross-site-scripting","description":"The Gravityforms plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.6 due to insufficient input sanitization and output escaping alongside the use of add_query_arg or remove_query_arg(). This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2015-04-20"}],"impact":[]},{"uuid":"099ddcf0f951dd8d87b2aa42950bd4f0ab3928245a75f0fccba1fa5d14d569f9","name":"Gravity Forms [gravityforms] >= 1.8 - <= 1.9.3.5","description":null,"operator":{"min_version":"1.8","min_operator":"ge","max_version":"1.9.3.5","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-2260","name":"CVE-2015-2260","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-2260","description":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.","date":"0000-00-00"},{"id":"ee2954015f3321bf091986c7a0030547efbe55cf","name":"Gravityforms <= 1.9.3.5 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravityforms-1935-sql-injection","description":"The Gravifyforms plugin for WordPress is vulnerable to blind SQL Injection via the \u2018sort_column GET\u2019 parameter in versions up to, and including,1.9.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2015-03-17"}],"impact":[]},{"uuid":"78d7d76dc10a97d97ef5702bd4331a4f5bc473619491f54d842f1fce66bcc00d","name":"Gravity Forms [gravityforms] < 1.8.20","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.20","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5d316e562603752eef544876b5b71512429a30a4","name":"Gravityforms <= 1.8.19 - Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravityforms-1819-arbitrary-file-upload","description":"The Gravityforms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the includes\/upload.php file in versions up to, and including, 1.8.19. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible","date":"2015-02-26"}],"impact":[]},{"uuid":"7d1e3e90811bd5eba80504325f11c6b7aa123117fbe2afdd95377b896a3ed4a0","name":"Gravity Forms [gravityforms] < 2.0.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"978f6645-9187-4548-99ae-be6422d2ba46","name":"Gravity Forms &lt;= 2.0.6.5 - Authenticated Blind Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/978f6645-9187-4548-99ae-be6422d2ba46","description":"A blind XSS vulnerability exists in the GravityForms plugin prior to version 2.0.7, in the select option dropdown boxes on forms. If the select column is displayed on the gf_entries page when viewed in the Dashboard, the code is executed by the admin \/ viewer of the submissions.\r\n\r\nThis vulnerability was responsibly disclosed to the vendor, with documentation, images, and proof of concept. Version 2.0.7 was delivered to the researcher to confirm the vulnerability had been patched, and an adequate timeframe was agreed upon with the vendor before public disclosure, to allow customers time to update their installations.","date":null}],"impact":[]},{"uuid":"586a7e13bec85e55596ffe33762d06b2ec7dfe3a0359071eb8337dca73788668","name":"Gravity Forms [gravityforms] < 1.9.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6faa2bf2-f76b-413b-bfab-e1292371cb57","name":"Gravity Forms &lt;= 1.9.15.11 - Authenticated Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/6faa2bf2-f76b-413b-bfab-e1292371cb57","description":"The gravityforms WordPress plugin was affected by a  Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"be1c551e24c4a2df61b75c4d404f14ef396159d56041ff37b411485fb2dd7d7e","name":"Gravity Forms [gravityforms] < 1.9.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"fa0a50d9-f6dd-4565-b00d-d1ff90539aea","name":"Gravity Forms &lt;= 1.9.6 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/fa0a50d9-f6dd-4565-b00d-d1ff90539aea","description":"The gravityforms WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"df87c7fc22c2be4d337239ced9d731fb867954fb10d87b7e2a647aaa49f18509","name":"Gravity Forms [gravityforms] < 1.9.3.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.3.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2652386e-a2e1-4fa9-bc64-4b85e1d84d78","name":"Gravity Forms 1.8 &lt;= 1.9.3.5 - Authenticated Blind SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/2652386e-a2e1-4fa9-bc64-4b85e1d84d78","description":"Title: Gravity Forms 1.8 &lt;= 1.9.3.5 - Blind SQL Injection CVE-2015-2260\r\n\r\nVersion\/s Tested: 1.9.3.1\r\n\r\nDescription:\r\nGravity Forms is one of the most popular WordPress plugins (gravityforms) used to create forms for WordPress sites. The latest version at the time of writing (1.9.3.5) contains an authenticated (admin, or user with gravityforms_edit_forms capability) Blind SQL Injection vulnerability. The plugin is one of the most popular plugins for the WordPress platform.\r\n\r\nTechnical Description: \r\nThe authenticated Blind SQL Injection vulnerability can be found within the &#039;form_list.php&#039; and &lsquo;forms_model&rsquo; files. The sort_column GET parameter is not sufficiently sanitised before being used within an SQL query.\r\n\r\nform_list.php line 106:\r\n$sort_column = empty( $_GET[&#039;sort&#039;] ) ? &#039;title&#039; : $_GET[&#039;sort&#039;];\r\n\r\nform_list.php line 111:\r\n$forms = RGFormsModel::get_forms( $active, $sort_column, $sort_direction, $trash );\r\n\r\nforms_model.php line 106:\r\n$sort_column  = ESC_SQL( $sort_column );\r\n$order_by     = ! empty( $sort_column ) ? &quot;ORDER BY $sort_column $sort_keyword&quot; : &#039;&#039;;\r\n$sql = &quot;SELECT f.id, f.title, f.date_created, f.is_active, 0 as lead_count, 0 view_count FROM $form_table_name f $where_clause $order_by&quot;;\r\n\r\nAccording to WordPress this function &#039;Prepares a string for use as an SQL query. A glorified addslashes() that works with arrays.&#039;. However, this is not sufficient to prevent SQL Injection as can be seen from the Proof of Concept.\r\n\r\nProof of Concept (PoC)\r\n\r\nThe following GET request will cause the SQL query to execute and sleep for 10 seconds if clicked on as an authenticated admin or other user with gravityforms_edit_forms capability.\r\n\r\nhttp:\/\/localhost\/wp-admin\/admin.php?page=gf_edit_forms&amp;sort=date_created%2c(select%20*%20from%20(select(sleep(10)))a)\r\n\r\nImpact:\r\nThe original impact has been amended after further research by Ryan Dewhurst. Due to WordPress using X-Frame-Options and PHP\/MySQL not supporting stacked queries, it is not currently possible to exploit this vulnerability by a remote attacker via CSRF. A reliable cross-domain timing attack using a GET request which does not rely on frames would be required to exploit this issue.\r\n\r\nFix for 1.8 branch:\r\nAfter form_list.php line 106:\r\n$sort_column    = empty( $_GET[&#039;sort&#039;] ) ? &#039;title&#039; : $_GET[&#039;sort&#039;];\r\n\r\nAdd:\r\nif ( ! in_array( strtolower( $sort_column ), array( &#039;id&#039;, &#039;title&#039;, &#039;date_created&#039;, &#039;is_active&#039;, &#039;is_trash&#039; ) ) ) {\r\n  $sort_column = &#039;title&#039;;\r\n}\r\n\r\n\r\nTimeline:\r\nMarch 13th: 2030 CST: Vulnerability Discovered by Scott Kingsley Clark (10up.com) and vendor notified.\r\nMarch 13th 2300 GMT-5: Review, exploit and temporary patch written by Ivan Kruchkoff (10up.com).\r\nMarch 14th: Vendor releases 1.9.3.6\r\nMarch 17th: Advisory released.\r\n\r\nCredits:\r\nRyan Dewhurst (WPScan Team - Dewhurst Security) for PoC \/ writeup of WP SEO exploit: CVE-2015-2292, CVE-2015-2293","date":null}],"impact":[]},{"uuid":"2c9d9d91dda5d5e069c4ffdebc8bce71f7d4d586559be326174a45d3bb4fa2f6","name":"Gravity Forms [gravityforms] < 1.8.20","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.20","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c3d81ea3-fdee-4ccb-8f4b-e203bab1f975","name":"Gravity Forms &lt;= 1.8.19 - Arbitrary File Upload","link":"https:\/\/wpscan.com\/vulnerability\/c3d81ea3-fdee-4ccb-8f4b-e203bab1f975","description":"The gravityforms WordPress plugin was affected by an Arbitrary File Upload security vulnerability.","date":null}],"impact":[]},{"uuid":"52ca2f48729836a401ca4044af78af03f68023ab37ce0b05fbf5184c68ec6fc1","name":"Gravity Forms [gravityforms] < 2.7.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-28782","name":"CVE-2023-28782","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-28782","description":"[en] Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n\/a through 2.7.3.","date":"2023-12-20"},{"id":"54f978a992bf3a2cc75b941489a302c9c6b91644","name":"WordPress  Gravity Forms  Plugin  <= 2.7.3 is vulnerable to PHP Object Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/gravityforms\/vulnerability\/wordpress-gravity-forms-plugin-2-7-3-unauthenticated-php-object-injection-vulnerability","description":"Update the WordPress Gravity Forms plugin to the latest available version (at least 2.7.4).\nRafie Muhammad (Patchstack) discovered and reported this PHP Object Injection vulnerability in WordPress Gravity Forms  Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of service, and more if a proper POP chain is present. This vulnerability has been fixed in version 2.7.4.","date":"2023-05-29"},{"id":"9356d622ba447956326fdb39897937c74c026ac9","name":"Gravity Forms  <= 2.7.3 - Unauthenticated PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-273-unauthenticated-php-object-injection","description":"The Gravity Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.7.3 via deserialization of untrusted input in the get_field_input function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2023-05-29"},{"id":"f27efbe4-ce05-4867-bc26-3cf165b7669b","name":"Gravity Forms &lt; 2.7.4 - Unauthenticated PHP Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/f27efbe4-ce05-4867-bc26-3cf165b7669b","description":"The plugin unserializes user input via the get_field_input(), which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"l","score":"8.3","severity":"h","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:L","score":"8.3","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"low","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}]}},{"uuid":"a0fb57e8358ed57c602dcc4f31ca902370bf90a7391ee6ccca6e527ed402c659","name":"Gravity Forms [gravityforms] < 2.7.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-2701","name":"CVE-2023-2701","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2701","description":"[en] The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.","date":"2023-07-17"},{"id":"d487db206316c729c71254a0571ef72ffb2b13da","name":"WordPress  Gravity Forms  Plugin  < 2.7.5 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/gravityforms\/vulnerability\/wordpress-gravity-forms-plugin-2-7-5-reflected-xss-vulnerability","description":"Update the WordPress Gravity Forms plugin to the latest available version (at least 2.7.5).\nFioravante Souza (WPScan) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gravity Forms  Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 2.7.5.","date":"2023-06-26"},{"id":"8d39d117734e52287fde22fafd06ddfdbe52da07","name":"Gravity Forms <= 2.7.4 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-274-reflected-cross-site-scripting","description":"The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2023-06-21"},{"id":"298fbe34-62c2-4e56-9bdb-90da570c5bbe","name":"Gravity Forms &lt; 2.7.5 - Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/298fbe34-62c2-4e56-9bdb-90da570c5bbe","description":"The plugin does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1b78802b1be96e80aa6ffb2bfb1849526edb9d0ef78da0a3ed9e235b17c900c0","name":"Gravity Forms [gravityforms] < 1.9.3.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.3.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"dc9bf3acf57fae6db13d237547ccc621c3b3b2e4","name":"WordPress  Gravity Forms  Plugin  <= 1.9.3.5 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/gravityforms\/vulnerability\/wordpress-gravity-forms-plugin-1-9-3-5-sql-injection","description":"Update the plugin.\nAn unknown person discovered and reported this SQL Injection vulnerability in WordPress Gravity Forms  Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 1.9.3.6.","date":"2023-03-17"}],"impact":[]},{"uuid":"6ce688c09af4867e97e5dea5c337f50f9cfec1e877d38fa7415864fc35374bfe","name":"Gravity Forms [gravityforms] < 1.9.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6be964f5c0006e77073ce0c732fc408a05d76a28","name":"WordPress  Gravity Forms  Plugin  <= 1.9.6 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/gravityforms\/vulnerability\/wordpress-gravity-forms-plugin-1-9-6-cross-site-scripting","description":"Update the plugin to the latest version.\nAn unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gravity Forms  Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 1.9.7.","date":"2023-04-20"}],"impact":[]},{"uuid":"dfe27bb684fc0d5ede457823a9f89cba7b42444b5dfc5e11fb692217b9d7639c","name":"Gravity Forms [gravityforms] < 1.9.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"52066b53e238a2ef78d02e8032a75c9d6fb677d4","name":"WordPress  Gravity Forms  Plugin  <= 1.9.15.11 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/gravityforms\/vulnerability\/wordpress-gravity-forms-1-9-15-11-authenticated-reflected-xss","description":"Update the plugin.\nHenri Salo discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gravity Forms  Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 1.9.16.","date":"2023-03-01"}],"impact":[]},{"uuid":"762aba5259cee10c8b26ab74635986d7dc0feaf3ec858ace1b5337f7e0ffb1a4","name":"Gravity Forms [gravityforms] < 1.8.20","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.20","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"478ef50996fe08bb6f773fa4dc74d295f8a5a20c","name":"WordPress  Gravity Forms  Plugin  <= 1.8.19 is vulnerable to Local File Inclusion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/gravityforms\/vulnerability\/wordpress-gravity-forms-plugin-1-8-19-arbitrary-file-upload","description":"Upgrade the plugin.\nAbk Khan discovered and reported this Local File Inclusion vulnerability in WordPress Gravity Forms  Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potentially allow complete database takeover depending on the configuration. This vulnerability has been fixed in version 1.8.20.","date":"2023-06-17"}],"impact":[]},{"uuid":"486d4dc6149bbf4d3f004820e2aa21dde3b21fff3d968bbe44dcc699d57e4e36","name":"Gravity Forms [gravityforms] < 2.0.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f89c6587384527c976f143ae63e13073a3a0dc54","name":"WordPress  Gravity Forms  Plugin  <= 2.0.6.5 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/gravityforms\/vulnerability\/wordpress-gravity-forms-plugin-2-0-6-5-xss","description":"Update the plugin.\nAn unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gravity Forms  Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 2.0.7.","date":"2023-10-13"}],"impact":[]},{"uuid":"168f98a78d602c22bd1ab5dd14737db96cf934d2c93f8624597c08193464cbef","name":"Gravity Forms [gravityforms] < 2.9.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-13377","name":"CVE-2024-13377","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-13377","description":"[en] The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018alt\u2019 parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-01-17"},{"id":"f686816f616d7f6dfca1e91da68adb485955de66","name":"GravityForms <= 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'alt' parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravityforms-2913-unauthenticated-stored-cross-site-scripting-via-alt-parameter","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018alt\u2019 parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-01-16"},{"id":"a90562c1f932864d2d396edc72afecc3372bda0a","name":"WordPress Gravity Forms Plugin <= 2.9.1.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/gravityforms\/vulnerability\/wordpress-gravityforms-plugin-2-9-1-3-unauthenticated-stored-cross-site-scripting-via-alt-parameter-vulnerability","description":"<p>WordPress Gravity Forms Plugin <= 2.9.1.3 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Gravity Forms<\/p><p>Fixed in version 2.9.2 <\/p><p>Affected Version <= 2.9.1.3<\/p><p>CVE: CVE-2024-13377<\/p>","date":"2025-01-16"},{"id":"EUVD-2024-51565","name":"EUVD-2024-51565","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-51565","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018alt\u2019 parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-01-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"3.9","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.9","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.003"}},{"uuid":"1d100663ecc5f741717895cd693776f644df1b26598745f0d8e99fabe5961d89","name":"Gravity Forms [gravityforms] < 2.9.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-13378","name":"CVE-2024-13378","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-13378","description":"[en] The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018style_settings\u2019 parameter in versions 2.9.0.1 up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attack is only successful in the Chrome web browser, and requires directly browsing the media file via the attachment post.","date":"2025-01-17"},{"id":"b980b137ea69f20790c89f5ec234becfc0baf70f","name":"GravityForms 2.9.0.1 - 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'style_settings' parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravityforms-2901-2913-unauthenticated-stored-cross-site-scripting-via-style-settings-parameter","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018style_settings\u2019 parameter in versions 2.9.0.1 up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attack is only successful in the Chrome web browser, and requires directly browsing the media file via the attachment post.","date":"2025-01-16"},{"id":"EUVD-2024-51566","name":"EUVD-2024-51566","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-51566","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018style_settings\u2019 parameter in versions 2.9.0.1 up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attack is only successful in the Chrome web browser, and requires directly browsing the media file via the attachment post.","date":"2025-01-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"h","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.2","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"high","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.2","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.002"}},{"uuid":"38362051bb8c79ee188f0754305d2289a72eb4bf68c7f0eb276cf98dd4645cee","name":"Gravity Forms [gravityforms] < 2.9.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-12352","name":"CVE-2025-12352","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-12352","description":"[en] The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This only impacts sites that have allow_url_fopen set to `On`, the post creation form enabled along with a file upload field for the post","date":"2025-11-07"},{"id":"c26226b1a33e7cecc8acd752a23515bf68f8d9f1","name":"Gravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via 'copy_post_image'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-2920-unauthenticated-arbitrary-file-upload-via-copy-post-image","description":"The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This only impacts sites that have allow_url_fopen set to `On`, the post creation form enabled along with a file upload field for the post","date":"2025-11-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"24fd8b99ad618dcdda5ff0562a215e16bd07a93386022ca43b11cd0f76691584","name":"Gravity Forms [gravityforms] < 2.9.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-12974","name":"CVE-2025-12974","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-12974","description":"[en] The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechanism in all versions up to, and including, 2.9.21.1. This is due to the extension blacklist not including .phar files, which can be uploaded through the chunked upload mechanism. This makes it possible for unauthenticated attackers to upload executable .phar files and achieve remote code execution on the server, granted they can discover or enumerate the upload path. In order for an attacker to achieve RCE, the web server needs to be set up to process .phar file as PHP via file handler mapping or similar.","date":"2025-11-18"},{"id":"2b5febffc00e59aad466ca68cd82fc9ec4b9e5b9","name":"Gravity Forms <= 2.9.21.1 - Unauthenticated Arbitrary File Upload via Legacy Chunked Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-29211-unauthenticated-arbitrary-file-upload-via-legacy-chunked-upload","description":"The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechanism in all versions up to, and including, 2.9.21.1. This is due to the extension blacklist not including .phar files, which can be uploaded through the chunked upload mechanism. This makes it possible for unauthenticated attackers to upload executable .phar files and achieve remote code execution on the server, granted they can discover or enumerate the upload path. In order for an attacker to achieve RCE, the web server needs to be set up to process .phar file as PHP via file handler mapping or similar.","date":"2025-11-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.1","severity":"h","exploitable":"2.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.1","severity":"high","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.2","impact":"5.9"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"3950a05df96459d093b7e54c8f062d3c34ddf209e211da54c2f203f9155f9e51","name":"Gravity Forms [gravityforms] < 2.9.23.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.23.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-13407","name":"CVE-2025-13407","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-13407","description":"[en] The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.","date":"2025-12-24"},{"id":"a1f5cd2689d1cfc110575758c03e50dd8fd932b6","name":"Gravity Forms <= 2.9.23.0 - Unauthenticated Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-29230-unauthenticated-arbitrary-file-upload","description":"The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 2.9.23.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.","date":"2025-12-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:N","av":"n","ac":"h","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"n","score":"6.8","severity":"m","exploitable":"1.6","impact":"5.2"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:N","score":"6.8","severity":"medium","av":"network","ac":"high","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"none","exploitable":"1.6","impact":"5.2"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"f782c90b1b364d866f1e1ee59fe0debbd3de17593eb5c753cd2e0181e74895ed","name":"Gravity Forms [gravityforms] < 2.9.31","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.31","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-4394","name":"Gravity Forms <= 2.9.30 - Unauthenticated Stored Cross-Site Scripting via Credit Card 'Card Type' Sub-Field","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-4394","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`) in all versions up to, and including, 2.9.30. This is due to the `get_value_entry_detail()` method in the `GF_Field_CreditCard` class outputting the card type value without escaping, combined with `get_value_save_entry()` accepting and storing unsanitized user input for the `input_<id>.4` parameter. The Card Type field is not rendered on the frontend form (it is normally derived from the card number), but the backend submission parser blindly accepts it if included in the POST request. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the form entry in the WordPress dashboard.","date":"0000-00-00"},{"id":"fab4c19741cab5053fad9e3cdb069a32474d0e69","name":"Gravity Forms <= 2.9.30 - Unauthenticated Stored Cross-Site Scripting via Credit Card 'Card Type' Sub-Field","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-2930-unauthenticated-stored-cross-site-scripting-via-credit-card-card-type-sub-field","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`) in all versions up to, and including, 2.9.30. This is due to the `get_value_entry_detail()` method in the `GF_Field_CreditCard` class outputting the card type value without escaping, combined with `get_value_save_entry()` accepting and storing unsanitized user input for the `input_<id>.4` parameter. The Card Type field is not rendered on the frontend form (it is normally derived from the card number), but the backend submission parser blindly accepts it if included in the POST request. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the form entry in the WordPress dashboard.","date":"2026-04-07"},{"id":"EUVD-2026-19990","name":"EUVD-2026-19990","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-19990","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`) in all versions up to, and including, 2.9.30. This is due to the `get_value_entry_detail()` method in the `GF_Field_CreditCard` class outputting the card type value without escaping, combined with `get_value_save_entry()` accepting and storing unsanitized user input for the `input_<id>.4` parameter. The Card Type field is not rendered on the frontend form (it is normally derived from the card number), but the backend submission parser blindly accepts it if included in the POST request. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the form entry in the WordPress dashboard.","date":"2026-04-08"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":null,"impact":null}}},{"uuid":"62091ec64d65389ebc9262ea5518f49d92d42593c0946231018efda5f391c43f","name":"Gravity Forms [gravityforms] < 2.9.31","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.31","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-4406","name":"Gravity Forms <= 2.9.30 - Reflected Cross-Site Scripting via 'form_ids' Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-4406","description":"The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This is due to the `GFCommon::send_json()` method outputting JSON-encoded data wrapped in HTML comment delimiters using `echo` and `wp_die()`, which serves the response with a `Content-Type: text\/html` header instead of `application\/json`. The `wp_json_encode()` function does not HTML-encode angle brackets within JSON string values, allowing injected HTML\/script tags in `form_ids` array values to be parsed and executed by the browser. The required `config_nonce` is generated with `wp_create_nonce('gform_config_ajax')` and is publicly embedded on every page that renders a Gravity Forms form, making it identical for all unauthenticated visitors within the same 12-hour nonce tick. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This vulnerability cannot be exploited against users who are authenticated on the target system, but could be used to alter the target page.","date":"0000-00-00"},{"id":"a3295e38bbdf602e8cfec2153330543ef365529b","name":"Gravity Forms <= 2.9.30 - Reflected Cross-Site Scripting via 'form_ids' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-2930-reflected-cross-site-scripting-via-form-ids-parameter","description":"The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This is due to the `GFCommon::send_json()` method outputting JSON-encoded data wrapped in HTML comment delimiters using `echo` and `wp_die()`, which serves the response with a `Content-Type: text\/html` header instead of `application\/json`. The `wp_json_encode()` function does not HTML-encode angle brackets within JSON string values, allowing injected HTML\/script tags in `form_ids` array values to be parsed and executed by the browser. The required `config_nonce` is generated with `wp_create_nonce('gform_config_ajax')` and is publicly embedded on every page that renders a Gravity Forms form, making it identical for all unauthenticated visitors within the same 12-hour nonce tick. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This vulnerability cannot be exploited against users who are authenticated on the target system, but could be used to alter the target page.","date":"2026-04-07"},{"id":"EUVD-2026-19994","name":"EUVD-2026-19994","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-19994","description":"The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This is due to the `GFCommon::send_json()` method outputting JSON-encoded data wrapped in HTML comment delimiters using `echo` and `wp_die()`, which serves the response with a `Content-Type: text\/html` header instead of `application\/json`. The `wp_json_encode()` function does not HTML-encode angle brackets within JSON string values, allowing injected HTML\/script tags in `form_ids` array values to be parsed and executed by the browser. The required `config_nonce` is generated with `wp_create_nonce('gform_config_ajax')` and is publicly embedded on every page that renders a Gravity Forms form, making it identical for all unauthenticated visitors within the same 12-hour nonce tick. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This vulnerability cannot be exploited against users who are authenticated on the target system, but could be used to alter the target page.","date":"2026-04-08"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.7","severity":"medium","av":"network","ac":"high","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":null,"impact":null}}},{"uuid":"775154e9b82bd949a5f3e7f4aa611f8e5919bea21d8caf73c431f1e1648d76db","name":"Gravity Forms [gravityforms] < 2.9.29","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.29","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-3492","name":"Gravity Forms <= 2.9.28.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3492","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a compound failure involving missing authorization on the `create_from_template` AJAX endpoint (allowing any authenticated user to create forms), insufficient input sanitization (`sanitize_text_field()` preserves single quotes), and missing output escaping when the form title is rendered in the Form Switcher dropdown (`title` attribute constructed without `esc_attr()`, and JavaScript `saferHtml` utility only escapes `&`, `<`, `>` but not quotes). This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary JavaScript that executes when an Administrator searches in the Form Switcher dropdown in the Form Editor.","date":"0000-00-00"},{"id":"a129c27a1bec994dffd1f4520de217536418ddbe","name":"Gravity Forms <= 2.9.28.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-29281-authenticated-subscriber-stored-cross-site-scripting-via-form-title","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a compound failure involving missing authorization on the `create_from_template` AJAX endpoint (allowing any authenticated user to create forms), insufficient input sanitization (`sanitize_text_field()` preserves single quotes), and missing output escaping when the form title is rendered in the Form Switcher dropdown (`title` attribute constructed without `esc_attr()`, and JavaScript `saferHtml` utility only escapes `&`, `<`, `>` but not quotes). This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary JavaScript that executes when an Administrator searches in the Form Switcher dropdown in the Form Editor.","date":"2026-03-10"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ffa597a8074beb59432655799a6c8878c376d663184c56e16930575e195e0630","name":"Gravity Forms [gravityforms] < 2.10.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5111","name":"CVE-2026-5111","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5111","description":"[en] The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fields, where repeater subfields bypass state validation checks and the Hidden Product validate() method only validates the quantity field while ignoring the product name field that is later output without proper escaping in the get_value_entry_detail() method. This makes it possible for unauthenticated attackers to inject arbitrary web scripts through form submissions that will execute whenever an administrator views the entry details.","date":"2026-05-02"},{"id":"76b2a436508e6fa0d215b0d8057758bcebec0a75","name":"Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Hidden Product Field in Repeater","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-2100-unauthenticated-stored-cross-site-scripting-via-hidden-product-field-in-repeater","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fields, where repeater subfields bypass state validation checks and the Hidden Product validate() method only validates the quantity field while ignoring the product name field that is later output without proper escaping in the get_value_entry_detail() method. This makes it possible for unauthenticated attackers to inject arbitrary web scripts through form submissions that will execute whenever an administrator views the entry details.","date":"2026-05-01"},{"id":"EUVD-2026-26743","name":"EUVD-2026-26743","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-26743","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fields, where repeater subfields bypass state validation checks and the Hidden Product validate() method only validates the quantity field while ignoring the product name field that is later output without proper escaping in the get_value_entry_detail() method. This makes it possible for unauthenticated attackers to inject arbitrary web scripts through form submissions that will execute whenever an administrator views the entry details.","date":"2026-05-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"fbd788a1931d0701736820b2a7b08cdf94e69e7e152e9a8a8cdfe041874e30ce","name":"Gravity Forms [gravityforms] < 2.10.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5110","name":"CVE-2026-5110","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5110","description":"[en] The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a Repeater field. When SingleProduct fields are nested within Repeater fields, the validation flow bypasses the state validation mechanism (failed_state_validation()) that would normally prevent tampering with field values. The validate_subfield() method only calls the field's validate() method, which for SingleProduct fields only validates the quantity field and does not check the product name field for tampering. As a result, an attacker can inject arbitrary HTML and JavaScript into the product name field (input .1). This malicious input is then saved to the database without sanitization because sanitize_entry_value() returns raw values when HTML is not expected for the field type. When an administrator views the entry in wp-admin\/admin.php?page=gf_entries, the get_value_entry_detail() method outputs the product name without escaping, causing the stored XSS payload to execute in the administrator's browser. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses an entry containing the malicious payload.","date":"2026-05-02"},{"id":"765e158b4ad268587d90dec9df417a8050666586","name":"Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Single Product Field Inside Repeater","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-2100-unauthenticated-stored-cross-site-scripting-via-single-product-field-inside-repeater","description":"The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a Repeater field. When SingleProduct fields are nested within Repeater fields, the validation flow bypasses the state validation mechanism (failed_state_validation()) that would normally prevent tampering with field values. The validate_subfield() method only calls the field's validate() method, which for SingleProduct fields only validates the quantity field and does not check the product name field for tampering. As a result, an attacker can inject arbitrary HTML and JavaScript into the product name field (input .1). This malicious input is then saved to the database without sanitization because sanitize_entry_value() returns raw values when HTML is not expected for the field type. When an administrator views the entry in wp-admin\/admin.php?page=gf_entries, the get_value_entry_detail() method outputs the product name without escaping, causing the stored XSS payload to execute in the administrator's browser. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses an entry containing the malicious payload.","date":"2026-05-01"},{"id":"EUVD-2026-26742","name":"EUVD-2026-26742","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-26742","description":"The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a Repeater field. When SingleProduct fields are nested within Repeater fields, the validation flow bypasses the state validation mechanism (failed_state_validation()) that would normally prevent tampering with field values. The validate_subfield() method only calls the field's validate() method, which for SingleProduct fields only validates the quantity field and does not check the product name field for tampering. As a result, an attacker can inject arbitrary HTML and JavaScript into the product name field (input .1). This malicious input is then saved to the database without sanitization because sanitize_entry_value() returns raw values when HTML is not expected for the field type. When an administrator views the entry in wp-admin\/admin.php?page=gf_entries, the get_value_entry_detail() method outputs the product name without escaping, causing the stored XSS payload to execute in the administrator's browser. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses an entry containing the malicious payload.","date":"2026-05-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"cfcb78dea7bb455c96f6e0731a8c8e10e0c9c676511c786e0dc78201260e7db7","name":"Gravity Forms [gravityforms] < 2.10.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5113","name":"CVE-2026-5113","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5113","description":"[en] The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.10.0. This is due to a flawed state validation mechanism that fails open when input is sanitized by wp_kses(), combined with insufficient output escaping. The state validation logic creates two hashes (raw input and wp_kses-sanitized input) and only fails validation if BOTH hashes don't match the original state. When an attacker injects XSS payloads using tags stripped by wp_kses() (like <svg>), the sanitized hash matches while the malicious raw value is preserved and saved to the database. When administrators view the Entries List page, the stored malicious consent label is retrieved and output without escaping, causing the XSS payload to execute. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in entries that will execute whenever an authenticated administrator accesses the entries list page.","date":"2026-05-02"},{"id":"4505a1988145b399166322b075c8b8a1d102cb3d","name":"Gravity Forms <= 2.9.30 - Unauthenticated Stored Cross-Site Scripting via Consent Field Hidden Input","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-2100-unauthenticated-stored-cross-site-scripting-via-consent-field-hidden-input","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.9.30. This is due to a flawed state validation mechanism that fails open when input is sanitized by wp_kses(), combined with insufficient output escaping. The state validation logic creates two hashes (raw input and wp_kses-sanitized input) and only fails validation if BOTH hashes don't match the original state. When an attacker injects XSS payloads using tags stripped by wp_kses() (like <svg>), the sanitized hash matches while the malicious raw value is preserved and saved to the database. When administrators view the Entries List page, the stored malicious consent label is retrieved and output without escaping, causing the XSS payload to execute. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in entries that will execute whenever an authenticated administrator accesses the entries list page.","date":"2026-05-01"},{"id":"EUVD-2026-26745","name":"EUVD-2026-26745","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-26745","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.10.0. This is due to a flawed state validation mechanism that fails open when input is sanitized by wp_kses(), combined with insufficient output escaping. The state validation logic creates two hashes (raw input and wp_kses-sanitized input) and only fails validation if BOTH hashes don't match the original state. When an attacker injects XSS payloads using tags stripped by wp_kses() (like <svg>), the sanitized hash matches while the malicious raw value is preserved and saved to the database. When administrators view the Entries List page, the stored malicious consent label is retrieved and output without escaping, causing the XSS payload to execute. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in entries that will execute whenever an authenticated administrator accesses the entries list page.","date":"2026-05-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"57fe5ff6a6571ee89782d69c36c7b76d2ffa4dfbc1d32d0151f3d557ad2bd068","name":"Gravity Forms [gravityforms] < 2.10.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5112","name":"CVE-2026-5112","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5112","description":"[en] The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names when rendered inside Repeater fields. The validate() method in the GF_Field_Calculation class only validates the quantity field (.3) and completely ignores the product name field (.1), allowing malicious HTML to pass through validation. When the value is saved, the sanitize_entry_value() method returns the raw value without sanitization for fields where HTML is not expected. Subsequently, when an entry is viewed in wp-admin, the get_value_entry_detail() method concatenates the unescaped product name directly into the output string, which is then rendered by the repeater's get_value_entry_detail() method without further escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts via form submissions that will execute whenever an authenticated administrator with the gravityforms_view_entries capability accesses the entry detail page.","date":"2026-05-02"},{"id":"c81da202d3cc89cfc69b38534a1aa7a92fdd5671","name":"Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Calculation Product Field in Repeater","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-2100-unauthenticated-stored-cross-site-scripting-via-calculation-product-field-in-repeater","description":"The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names when rendered inside Repeater fields. The validate() method in the GF_Field_Calculation class only validates the quantity field (.3) and completely ignores the product name field (.1), allowing malicious HTML to pass through validation. When the value is saved, the sanitize_entry_value() method returns the raw value without sanitization for fields where HTML is not expected. Subsequently, when an entry is viewed in wp-admin, the get_value_entry_detail() method concatenates the unescaped product name directly into the output string, which is then rendered by the repeater's get_value_entry_detail() method without further escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts via form submissions that will execute whenever an authenticated administrator with the gravityforms_view_entries capability accesses the entry detail page.","date":"2026-05-01"},{"id":"EUVD-2026-26744","name":"EUVD-2026-26744","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-26744","description":"The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names when rendered inside Repeater fields. The validate() method in the GF_Field_Calculation class only validates the quantity field (.3) and completely ignores the product name field (.1), allowing malicious HTML to pass through validation. When the value is saved, the sanitize_entry_value() method returns the raw value without sanitization for fields where HTML is not expected. Subsequently, when an entry is viewed in wp-admin, the get_value_entry_detail() method concatenates the unescaped product name directly into the output string, which is then rendered by the repeater's get_value_entry_detail() method without further escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts via form submissions that will execute whenever an authenticated administrator with the gravityforms_view_entries capability accesses the entry detail page.","date":"2026-05-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2cd8e5ddf22807bcae06e1c18b04778db7c3a5992ce0215f3d02248c5b5ba9d7","name":"Gravity Forms [gravityforms] < 2.10.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5109","name":"CVE-2026-5109","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5109","description":"[en] The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because the state validation function accepts submitted values where the wp_kses()-sanitized version matches a legitimate option value, but then stores the raw unsanitized value in the database. When administrators view entry details via the Order Summary section, the option_label is output directly without escaping (view-order-summary.php line 32), executing the injected JavaScript. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in entry data that will execute whenever an administrator accesses the entry details page.","date":"2026-05-02"},{"id":"e10481453283894cc5a75451f4aee95944e58ae9","name":"Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Product Option","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-2100-unauthenticated-stored-cross-site-scripting-via-product-option","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because the state validation function accepts submitted values where the wp_kses()-sanitized version matches a legitimate option value, but then stores the raw unsanitized value in the database. When administrators view entry details via the Order Summary section, the option_label is output directly without escaping (view-order-summary.php line 32), executing the injected JavaScript. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in entry data that will execute whenever an administrator accesses the entry details page.","date":"2026-05-01"},{"id":"EUVD-2026-26741","name":"EUVD-2026-26741","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-26741","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because the state validation function accepts submitted values where the wp_kses()-sanitized version matches a legitimate option value, but then stores the raw unsanitized value in the database. When administrators view entry details via the Order Summary section, the option_label is output directly without escaping (view-order-summary.php line 32), executing the injected JavaScript. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in entry data that will execute whenever an administrator accesses the entry details page.","date":"2026-05-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6adf4a48646de1b0aba714c6f8110588328166262f0650833026001d5184cdaf","name":"Gravity Forms [gravityforms] < 2.10.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-48866","name":"CVE-2026-48866","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-48866","description":"[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal.\n\nThis issue affects Gravity Forms: from n\/a through 2.10.0.1.","date":"2026-06-01"},{"id":"9acd8963cdb6407415f8403d635971bc5ac24686","name":"Gravity Forms <= 2.10.0.1 - Unauthenticated Arbitrary File Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/4e6b9ced-b303-43fe-8622-a32685f0a4ea","description":"The Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.10.0.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).","date":"2026-06-01"},{"id":"da020c9252f5a9d436c20ff522bb04693cad4f63","name":"Gravity Forms <= 2.10.0.1 - Unauthenticated Arbitrary File Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-21001-unauthenticated-arbitrary-file-deletion","description":"The Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.10.0.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).","date":"2026-07-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"h","i":"h","a":"h","score":"9.6","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:H\/I:H\/A:H","score":"9.6","severity":"critical","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"f3f23e116084af23035c368bbedb7d04df8f0606827fd31df411246161820588","name":"Gravity Forms [gravityforms] < 2.10.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-12997","name":"CVE-2026-12997","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-12997","description":"[en] The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the targeted form to not enforce login (so publicly accessible), which allows the unauthenticated attacker to reach the process_send_resume_link endpoint and supply an arbitrary recipient email address to receive the traversal-retrieved file as a notification attachment.","date":"2026-07-15"},{"id":"c95d6f73df5ca5454ae39aa4992ce3c9a10ff2a7","name":"Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-2104-unauthenticated-arbitrary-file-read-via-gform-uploaded-files-parameter","description":"The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the targeted form to not enforce login (so publicly accessible), which allows the unauthenticated attacker to reach the process_send_resume_link endpoint and supply an arbitrary recipient email address to receive the traversal-retrieved file as a notification attachment.","date":"2026-07-15"},{"id":"EUVD-2026-44761","name":"EUVD-2026-44761","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-44761","description":"The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the targeted form to not enforce login (so publicly accessible), which allows the unauthenticated attacker to reach the process_send_resume_link endpoint and supply an arbitrary recipient email address to receive the traversal-retrieved file as a notification attachment.","date":"2026-07-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"708316a1fa74ef21cafce72257790d177de1387d974ec3b562418e8921b4a471","name":"Gravity Forms [gravityforms] < 3.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-19513","name":"CVE-2026-19513","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-19513","description":"[en] The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in the `GFAsyncUpload::upload()` function, where public form state URL hashes can be reused as chunk continuation hashes and attacker-controlled temporary filenames are accepted before sanitization. This makes it possible for unauthenticated attackers, when a public form contains a File Upload field with Multiple Files enabled, to upload a valid PNG\/PDF polyglot to an attacker-selected public `.php` or `.html` filename in the Gravity Forms temporary upload directory. This can lead to remote code execution on WordPress systems that use NGINX or other non `.htaccess` respecting web servers. NOTE: During installation and activation, the Gravity Forms plugin places a `.htaccess` file in this directory, which prevents this vulnerability from being exploited despite the PHP file being written to the temporary upload directory. In these cases where PHP execution is blocked, attacker-written HTML can result in stored same-origin cross-site scripting if a victim visits the generated file URL.","date":"2026-09-01"},{"id":"3d1e1dd8b67aecec57d7aa3c0badc92bec1201b4","name":"Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload via State\/Chunk Hash Confusion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-302-unauthenticated-arbitrary-file-upload-via-statechunk-hash-confusion","description":"The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in the `GFAsyncUpload::upload()` function, where public form state URL hashes can be reused as chunk continuation hashes and attacker-controlled temporary filenames are accepted before sanitization. This makes it possible for unauthenticated attackers, when a public form contains a File Upload field with Multiple Files enabled, to upload a valid PNG\/PDF polyglot to an attacker-selected public `.php` or `.html` filename in the Gravity Forms temporary upload directory. This can lead to remote code execution on WordPress systems that use NGINX or other non `.htaccess` respecting web servers. NOTE: During installation and activation, the Gravity Forms plugin places a `.htaccess` file in this directory, which prevents this vulnerability from being exploited despite the PHP file being written to the temporary upload directory. In these cases where PHP execution is blocked, attacker-written HTML can result in stored same-origin cross-site scripting if a victim visits the generated file URL.","date":"2026-07-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.1","severity":"high","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"72390c99d3b7c231deca5fa7c7a4814d6e13327ddd8bb0e19452826064a856cd","name":"Gravity Forms [gravityforms] < 3.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-16649","name":"CVE-2026-16649","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-16649","description":"[en] The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit survives save-time sanitization because wp_kses_post allows the required HTML tags and attributes, and the client-side tooltip script re-parses the browser-decoded aria-label value as innerHTML while only stripping script elements, leaving onerror and other event-handler attributes fully intact and executable.","date":"2026-09-05"},{"id":"59b461d1087b0abc9af15a0c7aa79681b6b9d4c1","name":"Gravity Forms <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via Post Body Field Value","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-2105-unauthenticated-stored-cross-site-scripting-via-post-body-field-value","description":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit survives save-time sanitization because wp_kses_post allows the required HTML tags and attributes, and the client-side tooltip script re-parses the browser-decoded aria-label value as innerHTML while only stripping script elements, leaving onerror and other event-handler attributes fully intact and executable.","date":"2026-09-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d663270945da56b2f1d39ace62d699e66377b8de0e55de869daa37e0f90ddbe0","name":"Gravity Forms [gravityforms] < 3.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-84434","name":"CVE-2026-84434","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-84434","description":"[en] The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a rejected file's intact upload state is later passed to upload_file() without re-validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. Exploitation requires the targeted form to contain a File Upload field with its Visibility set to 'Hidden'; the vulnerability is reachable by unauthenticated attackers on any publicly accessible form meeting this condition.","date":"2026-09-19"},{"id":"fb66bcd3bb2bf513a639ee091b6542648eacd5c1","name":"Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/gravityforms\/gravity-forms-3104-unauthenticated-arbitrary-file-upload-via-hidden-file-upload-field","description":"The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a rejected file's intact upload state is later passed to upload_file() without re-validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. Exploitation requires the targeted form to contain a File Upload field with its Visibility set to 'Hidden'; the vulnerability is reachable by unauthenticated attackers on any publicly accessible form meeting this condition.","date":"2026-09-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}}]},"updated":"1789802895"}