Gravity Forms

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in Gravity Forms 2.9.20

    Fixed

    creation form. The Gravity Forms plugin for WordPress has a security issue that allows hackers to upload any type of file to a website using the plugin. This can lead to the execution of remote code ...

    Read More
  • Input validation vulnerability in Gravity Forms 2.9.21.1

    Fixed

    The Gravity Forms plugin for WordPress has a security issue that allows hackers to upload harmful files to a website. This happens because the plugin does not check the type of file being uploaded, w...

    Read More
  • Input validation vulnerability in Gravity Forms 2.9.1.3

    Fixed

    The Gravity Forms plugin for WordPress has a security issue where hackers can inject harmful code into a website using the 'alt' parameter. This can happen because the plugin does not properly clean ...

    Read More
  • Input validation vulnerability in Gravity Forms 2.9.1.3

    Fixed

    A plugin called Gravity Forms for WordPress has a security issue that allows hackers to insert harmful code into certain pages. This can happen in versions 2.9.0.1 through 2.9.1.3 because the plugin ...

    Read More
  • Input validation vulnerability in Gravity Forms 2.7.4

    Fixed

    The Gravity Forms plugin for WordPress is vulnerable to a type of attack, called Reflected Cross-Site Scripting. This type of attack can allow unauthenticated attackers to inject malicious web script...

    Read More
  • Output validation vulnerability in Gravityforms 2.7.3

    Fixed

    The Gravity Forms plugin for WordPress is not secure in versions up to 2.7.3. An attacker who is not logged in to WordPress can use this vulnerability to inject a malicious code. If the website has a...

    Read More
  • Input validation vulnerability in Gravityforms 1.9.6

    Fixed

    The Gravityforms plugin for WordPress can be vulnerable to Cross-Site Scripting in versions up to 1.9.6. This happens because the plugin does not properly sanitize and escape user input, and also mak...

    Read More
  • Input validation vulnerability in Gravityforms 2.0.6.5

    Fixed

    WordPress Plugin Gravity Forms is prone to a security issue called a cross-site scripting vulnerability. This means it doesn't protect user-supplied input properly. An attacker can use this to run ma...

    Read More
  • Access violation vulnerability in Gravityforms 2.4.8

    Fixed

    A bug in the Gravity Forms plugin for WordPress before version 2.4.9 could cause passwords to be accidentally shared. This happened because passwords were not treated as a special case when the plugin...

    Read More
  • Input validation vulnerability in Gravityforms 1.9.15.11

    Fixed

    The Gravityforms plugin for WordPress is not secure against malicious users. This plugin has a vulnerability that allows someone to insert malicious code into webpages if they can get a user to click...

    Read More
  • Input validation vulnerability in Gravityforms 1.8.20

    Fixed

    . The Gravityforms plugin for WordPress has a vulnerability that allows attackers to upload files to the server that runs the website. This issue affects versions up to and including 1.8.19 and could ...

    Read More
  • Input validation vulnerability in Gravityforms 1.9.3.5

    Fixed

    The Gravifyforms plugin for WordPress is not safe to use in versions up to and including 1.9.3.5. Attackers who are logged in can add extra bits of code to the existing code that can be used to get pr...

    Read More