CVE Tools

Crmperks

15 CVEs tracked since 2023. Since Dec 2023, none of them reached CISA KEV.

Crmperks CVEs per month

Dec 2023 to Dec 2025. Point at a month, or focus the strip and use the arrow keys.
Crmperks CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-1250
2024-01null or fewer
2024-02null or fewer
2024-0340
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-1260

Products

The products that kept showing up in Crmperks's monthly top three, with their CVEs summed over those months.

  1. Crm Perks Forms31 month
  2. Database For Contact Form 7, Wpforms, Elementor Forms11 month
  3. Database For Contact Form 7\, Wpforms\, Elementor Forms11 month
  4. Integration For Constant Contact and Contact Form 7\, Wpforms\, Elementor\, Ninja11 month
  5. Integration For Salesforce and Contact Form 7\, Wpforms\, Elementor\, Ninja Forms11 month
  6. Wp Gravity Forms Constant Contact Plugin11 month
  7. Wp Gravity Forms Freshdesk Plugin11 month
  8. Wp Gravity Forms Insightly11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Crmperks.

  1. CVE-2026-9145Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value'6.5
  2. CVE-2026-9843Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value8.1
  3. CVE-2026-3831Database for Contact Form 7, WPforms, Elementor forms <= 1.4.9 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode4.3
  4. CVE-2026-2599Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP Object Injection via 'download_csv'9.8
  5. CVE-2026-2568WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.5 - Unauthenticated Stored Cross-Site Scripting7.2
  6. CVE-2026-0825Database for Contact Form 7, WPforms, Elementor forms <= 1.4.5 - Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export5.3
  7. CVE-2025-60180WordPress WP Gravity Forms Salesforce plugin <= 1.5.1 - PHP Object Injection vulnerability9.8
  8. CVE-2025-60178WordPress WP Gravity Forms HubSpot plugin <= 1.2.6 - Deserialization of untrusted data vulnerability9.8
  9. CVE-2025-60089WordPress WP Gravity Forms FreshDesk plugin plugin <= 1.3.5 - Deserialization of untrusted data vulnerability9.8
  10. CVE-2025-60174WordPress WP Gravity Forms Constant Contact plugin plugin <= 1.1.2 - Deserialization of untrusted data vulnerability9.8
  11. CVE-2025-60091WordPress WP Gravity Forms Zoho CRM and Bigin plugin <= 1.2.9 - Deserialization of untrusted data vulnerability9.8
  12. CVE-2025-60090WordPress WP Gravity Forms Insightly plugin <= 1.1.6 - Deserialization of untrusted data vulnerability9.8
  13. CVE-2025-7384Database for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP Object Injection to Arbitrary File Deletion9.8
  14. CVE-2025-7697Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 - Unauthenticated PHP Object Injection via verify_field_val Function9.8
  15. CVE-2025-7696Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.2.3 - Unauthenticated PHP Object Injection via verify_field_val Function9.8

The record

Peak rank
#141 in Dec 2023
Busiest month shown
Dec 2025, 6 CVEs
Months with a KEV entry
0 since Dec 2023
Monthly snapshots
3 since 2023
Crmperks's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store