Known Vulnerabilities for Gravity Forms by Mediaburst
Listed below are 3 of the newest known vulnerabilities associated with "Gravity Forms" by "Mediaburst".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-5113 json | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versio... | Not Provided | 2026-05-02 | 2026-05-04 |
| CVE-2026-5112 json | The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and inc... | Not Provided | 2026-05-02 | 2026-05-04 |
| CVE-2026-5111 json | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. T... | Not Provided | 2026-05-02 | 2026-05-04 |
| CVE-2026-5110 json | The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and inc... | Not Provided | 2026-05-02 | 2026-05-04 |
| CVE-2026-5109 json | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. T... | Not Provided | 2026-05-02 | 2026-05-04 |
| CVE-2026-4406 json | The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `g... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-4394 json | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' s... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-3492 json | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9... | Not Provided | 2026-03-11 | 2026-04-08 |
| CVE-2026-1396 json | The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'magic-con... | Not Provided | 2026-04-08 | 2026-04-13 |
| CVE-2025-67587 json | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk... | Not Provided | 2025-12-09 | 2026-04-27 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mediaburst | Gravity Forms | 2.4.0 | |||
| Application | Mediaburst | Gravity Forms | 2.2 | |||
| Application | Mediaburst | Gravity Forms | 2.1.2 | |||
| Application | Mediaburst | Gravity Forms | 2.1.1 | |||
| Application | Mediaburst | Gravity Forms | 2.1.0 | |||
| Application | Mediaburst | Gravity Forms | 2.0.3 | |||
| Application | Mediaburst | Gravity Forms | 2.0.2 | |||
| Application | Mediaburst | Gravity Forms | 2.0.1 | |||
| Application | Mediaburst | Gravity Forms | 2.0.0 | |||
| Application | Mediaburst | Gravity Forms | 1.0.1 | |||
| Application | Mediaburst | Gravity Forms | 1.0.0 | |||
| Application | Mediaburst | Gravity Forms | - |