Known Vulnerabilities for Forminator by Incsub
Listed below are 10 of the newest known vulnerabilities associated with "Forminator" by "Incsub".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82220 json | Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions. | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-66583 json | Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-57815 json | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMU DEV - Your All-in-One Wo... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-57814 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-56071 json | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions. | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-28143 json | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-28111 json | Contributor Privilege Escalation in Forminator <= 1.56.0 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-19222 json | The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to regis... | Not Provided | 2026-08-22 | 2026-08-23 |
| CVE-2026-19221 json | The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, al... | Not Provided | 2026-08-22 | 2026-08-23 |
| CVE-2026-19220 json | The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before ... | Not Provided | 2026-08-26 | 2026-08-26 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Incsub | Forminator | 1.7.0.1 | |||
| Application | Incsub | Forminator | 1.7.0 | |||
| Application | Incsub | Forminator | 1.6.3 | |||
| Application | Incsub | Forminator | 1.6.2 | |||
| Application | Incsub | Forminator | 1.6.1 | |||
| Application | Incsub | Forminator | 1.6.0.3 | |||
| Application | Incsub | Forminator | 1.6.0.2 | |||
| Application | Incsub | Forminator | 1.6.0.1 | |||
| Application | Incsub | Forminator | 1.6 | |||
| Application | Incsub | Forminator | 1.5.4 | |||
| Application | Incsub | Forminator | 1.5.3.1 | |||
| Application | Incsub | Forminator | 1.5.3 | |||
| Application | Incsub | Forminator | 1.5.2 | |||
| Application | Incsub | Forminator | 1.5.1 | |||
| Application | Incsub | Forminator | 1.5.0 | |||
| Application | Incsub | Forminator | 1.4.0 | |||
| Application | Incsub | Forminator | 1.3.0 | |||
| Application | Incsub | Forminator | 1.2.1 | |||
| Application | Incsub | Forminator | 1.2.0 | |||
| Application | Incsub | Forminator | 1.1.0 |