Fluentforms
9 CVEs tracked since 2024. Since May 2024, none of them reached CISA KEV.
Fluentforms CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2024-05 | 5 | 0 |
| 2024-06 | null or fewer | |
| 2024-07 | 4 | 0 |
Products
The products that kept showing up in Fluentforms's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Fluentforms.
- CVE-2024-10646Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject7.2
- CVE-2024-9651Contact Form Plugin by Fluent Forms < 5.2.1 - Admin+ Stored XSS6.1
- CVE-2024-9528Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scripting4.9
- CVE-2024-5053Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification4.2
- CVE-2024-6703Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Welcome Screen Fields4.9
- CVE-2024-6518Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting5.5
- CVE-2024-6520Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting5.5
- CVE-2024-6521Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting5.5
- CVE-2024-4157Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via extractDynamicValues7.5
- CVE-2024-4709Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting7.2
- CVE-2024-2772Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting6.4
- CVE-2024-2782Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation7.5
- CVE-2024-2771Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation9.8
- CVE-2023-6957Fluent Forms <= 5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting4.9
- CVE-2024-0618Fluent Forms <= 5.1.5 - Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title4.4
The record
- Peak rank
- #173 in Jul 2024
- Busiest month shown
- May 2024, 5 CVEs
- Months with a KEV entry
- 0 since May 2024
- Monthly snapshots
- 2 since 2024