Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free

Explore Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free vulnerabilities across all versions. Currently tracking 19 known vulnerabilities, including severity, impact, and patch status.

01234567891018.07.2023Today18.07.20236.1Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get CVSS 6.1 · 18.07.202318.09.20236.5Funnelforms Free <= 3.3.9 - Unauthenticated Stored Cross-Site Scripting CVSS 6.5 · 18.09.202301.11.20234.3Funnelforms Free <= 3.4 - Missing Authorization to Category Update CVSS 4.3 · 01.11.20236.5Funnelforms Free <= 3.4 - Missing Authorization to Arbitrary Post Deletion CVSS 6.5 · 01.11.20234.3Funnelforms Free <= 3.4 - Missing Authorization to Post Modification CVSS 4.3 · 01.11.20234.3Funnelforms Free <= 3.4 - Missing Authorization to Category Deletion CVSS 4.3 · 01.11.20234.3Funnelforms Free <= 3.4 - Missing Authorization to Enable/Disable Dark Mode CVSS 4.3 · 01.11.20234.3Funnelforms Free <= 3.4 - Cross-Site Request Forgery to Arbitrary Post Duplication CVSS 4.3 · 01.11.20234.3Funnelforms Free <= 3.4 - Missing Authorization to Arbitrary Post Duplication CVSS 4.3 · 01.11.20234.3Funnelforms Free <= 3.4 - Missing Authorization to Test Email Sending CVSS 4.3 · 01.11.20234.3Funnelforms Free <= 3.4 - Missing Authorization to New Category Creation CVSS 4.3 · 01.11.20236.5Funnelforms Free <= 3.4 - Cross-Site Request Forgery to Arbitrary Post Deletion CVSS 6.5 · 01.11.202327.08.20245.3Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary Media Upload CVSS 5.3 · 27.08.20247.2Funnelforms Free <= 3.7.3.2 - Authenticated (Administrator+) Arbitrary File Upload CVSS 7.2 · 27.08.20246.5Funnelforms Free <= 3.7.3.2 - Authenticated (Administrator+) Arbitrary File Deletion CVSS 6.5 · 27.08.202428.08.20245.3Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary Media Deletion CVSS 5.3 · 28.08.202403.12.20248.8Funnelforms Free <= 3.7.5.1 - Authenticated (Contributor+) PHP Object Injection CVSS 8.8 · 03.12.202425.12.20255.3Funnelforms Free <= 3.8 - Missing Authorization CVSS 5.3 · 25.12.202531.12.20256.4Funnelforms Free <= 3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 31.12.2025

Strategic Overview

Avg CVSSMedium
5.5/ 10
Patch Coverage84%
Open

3

Fixed

16

Get automatic notifications for all Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free vulnerabilities before they are exploited.

Vulnerability Records

19 records
2025-12-31 00:00CVE-2025-62758
6.4
Medium
Muhammad Yudha - DJNo
2025-12-25 00:00CVE-2025-68582
5.3
Medium
Legion HunterNo
2024-12-03 14:17CVE-2024-10587
8.8
High
Peter ThaleikisNo
2024-08-28 00:00CVE-2024-5857
5.3
Medium
Lucio SáYes
2024-08-27 00:00CVE-2024-7447
5.3
Medium
Lucio SáYes
2024-08-27 00:00CVE-2024-6311
7.2
High
István MártonYes
2024-08-27 00:00CVE-2024-6312
6.5
Medium
István MártonYes
2023-11-01 00:00CVE-2023-5417
4.3
Medium
Alex ThomasYes
2023-11-01 00:00CVE-2023-5386
6.5
Medium
Alex ThomasYes
2023-11-01 00:00CVE-2023-5411
4.3
Medium
Alex ThomasYes
Showing 1–10 of 19 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C