Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.3
CVE-2025-4208
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code Execution in all versions up t…
Nex Forms
after 8.9.2
MEDIUM 5.4
CVE-2025-3468
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the clean_h…
Nex Forms
8.9.2+
HIGH 7.2
CVE-2024-53808
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-build…
Nex Forms
8.7.9+
MEDIUM 6.1
CVE-2024-47389
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-build…
Nex Forms
8.7.4+
MEDIUM 5.4
CVE-2024-37512
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Basix NEX-Forms – Ultimate Form Builder …
Nex Forms
8.6.1+
MEDIUM 5.4
CVE-2024-25593
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms – Ultimate Form Builder allows …
Nex Forms
8.5.6+
HIGH 8.8
CVE-2023-52120
Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms – Ultimate Form Builder – Contact forms and much more.This issue affects NEX-Forms…
Nex Forms
after 8.5.2
HIGH 7.2
CVE-2023-50838
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder – Conta…
Nex Forms
after 8.5.5
MEDIUM 5.4
CVE-2023-0439
The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only Su…
Nex Forms
8.4.4+
HIGH 7.2
CVE-2023-2114EPSS 45%
The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it…
Nex Forms
8.4+
MEDIUM 5.4
CVE-2023-0272
The NEX-Forms WordPress plugin before 8.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …
Nex Forms
8.3.3+
MEDIUM 6.3
CVE-2020-36670
The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including 7.7.1 due to m…
Nex Forms
after 7.7.1
HIGH 8.8
CVE-2022-3142EPSS 11%
The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL inject…
Nex Forms
7.9.7+
HIGH 7.5
CVE-2021-34675
Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.
Nex Forms
after 7.8.7
HIGH 7.5
CVE-2021-34676
Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.
Nex Forms
after 7.8.7
CRITICAL 9.8
CVE-2015-9452
The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id…
Nex Forms
4.6.1+