Forminator Forms – Contact Form, Payment Form & Custom Form Builder
31 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Forminator Forms – Contact Form, Payment Form & Custom Form Builder, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Forminator Forms – Contact Form, Payment Form & Custom Form Builder CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 4 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 1 |
| 2025-02 | 1 |
| 2025-03 | 0 |
| 2025-04 | 2 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 3 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 4 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 6 |
| 2026-09 | 1 |
Severity
How the 31 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High10
- Medium18
Latest CVEs
The 15 most recently published vulnerabilities affecting Forminator Forms – Contact Form, Payment Form & Custom Form Builder.
- CVE-2026-92229Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter9.1
- CVE-2026-18324Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field7.2
- CVE-2026-18328Forminator Forms <= 1.57.0 - Unauthenticated DOM-Based Cross-Site Scripting via 'error_description' Parameter7.2
- CVE-2026-18323Forminator Forms <= 1.57.0.2 - Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft)7.2
- CVE-2026-15748Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration9.8
- CVE-2026-12998Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter5.3
- CVE-2026-18325Forminator Forms <= 1.56.1 - Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field7.2
- CVE-2026-6214Forminator Forms <= 1.53.0 - Missing Authorization to Authenticated (Subscriber+) Scheduled Form Submission Export via forminator_export_entries Action on wp_loaded Hook6.5
- CVE-2026-6222Forminator Forms <= 1.51.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'forminator_action' Parameter5.3
- CVE-2026-5192Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.52.1 - Unauthenticated Arbitrary File Read via 'upload-1[file][file_path]'7.5
- CVE-2026-2729Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.52.0 - Missing Authorization to Unauthenticated Stripe PaymentIntent Reuse / Underpayment Bypass via 'paymentid' Parameter5.3
- CVE-2026-2002Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.50.2 - Authenticated (Administrator+) Stored Cross-Site Scripting4.4
- CVE-2025-14782Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.49.1 - Missing Authorization to Authenticated (Forminator User+) CSV Export5.3
- CVE-2025-7638Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.45.0 - Authenticated (Administrator+) SQL Injection via `order_by` Parameter4.9
- CVE-2025-6464Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion7.5
Product grouping is registry-driven, with AI assist and human review. How it works