PatchSiren

Gravity Forms CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Gravity Forms CVE published 2026-09-05

CVE-2026-16649

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts, which can be executed when a user accesses an injected page. The plugin's insufficient input sanitization and output escaping enable this exploit. The vulnerability ha [truncated]

MEDIUM Gravity Forms CVE published 2026-04-08

CVE-2026-4406

The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The requir [truncated]

MEDIUM Gravity Forms CVE published 2026-04-08

CVE-2026-4394

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field in all versions up to, and including, 2.9.30. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the form entry in the WordPress dashboard. The vulnerability has a CVSS score of 6.1 and is classified [truncated]