Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-13407 2 Gravityforms, Wordpress 2 Gravity Forms, Wordpress 2025-12-29 6.8 Medium
The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.
CVE-2023-28782 1 Gravityforms 1 Gravity Forms 2024-11-21 8.3 High
Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.