Перейти к содержимому
Noroxi

NEX-Forms – Ultimate Forms Plugin for WordPress

nex-forms-express-wp-form-builder · плагин

Известные уязвимости для NEX-Forms – Ultimate Forms Plugin for WordPress. Узнайте за секунды, какая версия работает на вашем сайте, с WP Lens.

31 известных уязвимостей

1 критичных · последняя 18 сент. 2026 г.

Уязвимости

  • CVE-2015-9452

    The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex

    Критич. 9.8
  • CVE-2025-49399

    WordPress NEX-Forms Plugin <= 9.1.3 - Cross Site Request Forgery (CSRF) Vulnerability

    Высокий 8.8
  • CVE-2023-52120

    WordPress NEX-Forms – Ultimate Form Builder Plugin <= 8.5.2 is vulnerable to Cross Site Request Forgery (CSRF)

    Высокий 8.8
  • CVE-2026-15450

    NEX-Forms <= 9.2.3 - Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' Parameter

    Высокий 8.1
  • CVE-2026-1947

    NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id

    Высокий 7.5
  • CVE-2026-13040

    NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter

    Высокий 7.2
  • CVE-2026-12142

    NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter

    Высокий 7.2
  • CVE-2026-5063

    NEX-Forms <= 9.1.11 - Unauthenticated Stored Cross-Site Scripting via POST Parameter Key Names

    Высокий 7.2
  • CVE-2024-53808

    WordPress NEX-Forms plugin <= 8.7.8 - SQL Injection vulnerability

    Высокий 7.2
  • CVE-2023-50838

    WordPress NEX-Forms – Ultimate Form Builder Plugin <= 8.5.5 is vulnerable to SQL Injection

    Высокий 7.2
  • CVE-2026-57668

    WordPress NEX-Forms plugin <= 9.2.2 - Cross Site Scripting (XSS) vulnerability

    Высокий 7.1
  • CVE-2025-69326

    WordPress NEX-Forms plugin <= 9.1.7 - Reflected Cross Site Scripting (XSS) vulnerability

    Высокий 7.1
  • CVE-2025-69324

    WordPress NEX-Forms plugin <= 9.1.7 - Cross Site Scripting (XSS) vulnerability

    Высокий 7.1
  • CVE-2025-4208

    NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Limited Code Execution via get_table_records Function

    Средний 6.3
  • CVE-2024-47389

    WordPress NEX-Forms plugin <= 8.7.3 - Reflected Cross Site Scripting (XSS) vulnerability

    Средний 6.1
  • CVE-2025-3468

    NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Stored Cross-Site Scripting

    Средний 5.4
  • CVE-2024-37512

    WordPress NEX-Forms – Ultimate Form Builder plugin <= 8.5.10 - Cross Site Scripting (XSS) vulnerability

    Средний 5.4
  • CVE-2024-25593

    WordPress NEX-Forms plugin <= 8.5.5 - Cross Site Scripting (XSS) vulnerability

    Средний 5.4
  • CVE-2026-9017

    NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action

    Средний 5.3
  • CVE-2026-12404

    NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class

    Средний 5.3
  • CVE-2025-15510

    NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure

    Средний 5.3
  • CVE-2024-13498

    NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitive Information Exposure

    Средний 5.3
  • CVE-2026-75961

    NEX-Forms <= 9.3.0 - Authenticated (Administrator+) SQL Injection via 'operator' Key of the 'additional_params' Parameter

    Средний 4.9
  • CVE-2026-15602

    NEX-Forms <= 9.2.4 - Authenticated (Admin+) SQL Injection via 'additional_params' Parameter

    Средний 4.9
  • CVE-2026-7046

    NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.12 - Authenticated (Administrator+) SQL Injection via 'table' Parameter

    Средний 4.9
  • CVE-2025-10185

    NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.6 - Authenticated (Admin+) SQL Injection

    Средний 4.9
  • CVE-2024-10862

    NEX-Forms <= 8.7.15 - Authenticated (Admin+) SQL Injection

    Средний 4.9
  • CVE-2026-1948

    NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license

    Средний 4.3
  • CVE-2024-1130

    NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_read()

    Средний 4.3
  • CVE-2024-1129

    NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_starred()

    Средний 4.3
  • CVE-2024-0907

    NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via restore_records()

    Средний 4.3

← К каталогу