Known Vulnerabilities for Forms Server by Microsoft
Listed below are 1 of the newest known vulnerabilities associated with "Forms Server" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-87796 json | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and i... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-85692 json | Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vulnerabi... | Not Provided | 2026-09-04 | 2026-09-04 |
| CVE-2026-84218 json | A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs... | Not Provided | 2026-09-01 | 2026-09-02 |
| CVE-2026-82757 json | Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who contr... | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-80350 json | OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms, but... | Not Provided | 2026-08-26 | 2026-08-29 |
| CVE-2026-79749 json | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoint... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-78657 json | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-76172 json | fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-es... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-73644 json | OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-... | Not Provided | 2026-08-13 | 2026-08-18 |
| CVE-2026-73532 json | Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served throug... | Not Provided | 2026-08-13 | 2026-08-14 |