CVE Tools

Incsub

5 CVEs tracked since 2024. Since Apr 2024, none of them reached CISA KEV.

Incsub CVEs per month

Apr 2024 to Apr 2024. Point at a month, or focus the strip and use the arrow keys.
Incsub CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-0450

Products

The products that kept showing up in Incsub's monthly top three, with their CVEs summed over those months.

  1. Forminator51 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Incsub.

  1. CVE-2025-6464Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion7.5
  2. CVE-2025-6463Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion8.8
  3. CVE-2024-43118WordPress Hummingbird plugin <= 3.9.1 - Broken Access Control vulnerability4.3
  4. CVE-2024-45625Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows ...6.1
  5. CVE-2024-7389Forminator <= 1.29.1 - HubSpot Developer API Key Sensitive Information Exposure7.5
  6. CVE-2024-32792WordPress Hummingbird plugin <= 3.7.3 - Broken Access Control vulnerability4.3
  7. CVE-2024-28890Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by acces...5.3
  8. CVE-2024-31077Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain and alter any info...7.2
  9. CVE-2024-31857Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain user information etc. and alter the page contents on the u...5.4
  10. CVE-2024-1794Forminator <= 1.29.0 - Unauthenticated Stored Cross-Site Scripting via File Upload7.2
  11. CVE-2024-3053Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.29.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via forminator_form Shortcode6.4
  12. CVE-2024-29777WordPress Forminator plugin <= 1.29.0 - Reflected Cross Site Scripting (XSS) vulnerability7.1
  13. CVE-2023-5119Forminator and Forminator Pro < 1.27.0 - Admin+ Stored Cross-Site Scripting4.8
  14. CVE-2023-6133Forminator <= 1.27.0 - Authenticated (Administrator+) Arbitrary File Upload6.6
  15. CVE-2023-4596Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload9.8

The record

Peak rank
#169 in Apr 2024
Busiest month shown
Apr 2024, 5 CVEs
Months with a KEV entry
0 since Apr 2024
Monthly snapshots
1 since 2024
Incsub's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store