CVE-2026-5109
Gravity Forms
Minimum safe version
2.10.1
Update to 2.10.1 or later to address 30 fixable vulnerabilities
CVE-2026-5112
CVE-2026-5113
CVE-2026-5110
CVE-2026-5111
Gravity Forms <= 2.9.28.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title
Gravity Forms <= 2.9.30 - Reflected Cross-Site Scripting via 'form_ids' Parameter
Gravity Forms <= 2.9.30 - Unauthenticated Stored Cross-Site Scripting via Credit Card 'Card Type' Sub-Field
CVE-2025-13407
CVE-2025-12974
CVE-2025-12352
CVE-2024-13378
CVE-2024-13377
WordPress Gravity Forms Plugin <= 2.0.6.5 is vulnerable to Cross Site Scripting (XSS)
WordPress Gravity Forms Plugin <= 1.8.19 is vulnerable to Local File Inclusion
WordPress Gravity Forms Plugin <= 1.9.15.11 is vulnerable to Cross Site Scripting (XSS)
WordPress Gravity Forms Plugin <= 1.9.6 is vulnerable to Cross Site Scripting (XSS)
WordPress Gravity Forms Plugin <= 1.9.3.5 is vulnerable to SQL Injection
CVE-2023-2701
CVE-2023-28782
Gravity Forms <= 1.8.19 - Arbitrary File Upload
Gravity Forms 1.8 <= 1.9.3.5 - Authenticated Blind SQL Injection
Gravity Forms <= 1.9.6 - Cross-Site Scripting (XSS)
Gravity Forms <= 1.9.15.11 - Authenticated Reflected Cross-Site Scripting (XSS)
Gravity Forms <= 2.0.6.5 - Authenticated Blind Cross-Site Scripting (XSS)
Gravityforms <= 1.8.19 - Arbitrary File Upload
Gravityforms <= 1.9.3.5 - SQL Injection
Gravityforms <= 1.9.6 - Cross-Site Scripting
Gravityforms <= 1.9.15.11 - Cross-Site Scripting
Gravity Forms <= 2.0.6.5 - Cross-Site Scripting
CVE-2020-13764