Products: 4
    Vulnerabilities: 28
    Known Exploited: 0
    2
    Critical Level Threats
    10
    High Level Threats
    15
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-6464

    Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion

    Last Modified: Apr 22, 2026
    Published: Jul 02, 2025

    CVE-2025-6463

    Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion

    Last Modified: Apr 22, 2026
    Published: Jul 02, 2025

    CVE-2024-43118

    WordPress Hummingbird plugin <= 3.9.1 - Broken Access Control vulnerability

    Last Modified: Apr 23, 2026
    Published: Nov 01, 2024

    CVE-2024-10402

    Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation

    Last Modified: Apr 08, 2026
    Published: Oct 26, 2024

    CVE-2024-45625

    Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows a crafted URL and accesses the webpage with the web form created by Forminator.

    Last Modified: Mar 26, 2025
    Published: Sep 09, 2024
    Items Per Page
    Incsub Vulnerabilities & Security CVEs | CVE-DB