Known Vulnerabilities for Gravity Forms by Gravity Forms
Listed below are 10 of the newest known vulnerabilities associated with "Gravity Forms" by "Gravity Forms".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-74004 json | Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions. | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-61955 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی ف�... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-32466 json | Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-19513 json | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. Th... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2026-16649 json | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions... | Not Provided | 2026-09-05 | 2026-09-05 |
| CVE-2026-16635 json | The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-12997 json | The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via ... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-12477 json | The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... | Not Provided | 2026-08-16 | 2026-08-17 |
| CVE-2026-5581 json | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versi... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-2508 json | The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in ... | Not Provided | 2026-06-25 | 2026-06-25 |