Gravity Forms

Gravity Forms has 25 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2026; all 25 are fixed as of September 2026. Their average CVSS score is 7.3, and the most serious one scores 9.8 out of 10. Severity breakdown: 6 critical and 11 high. 2026 was the busiest year with 12 disclosures.

The most common weakness is Cross-Site Scripting, behind 15 of the records (60%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type, Path Traversal.

Every one of the 25 issues recorded for Gravity Forms has a vendor fix available, so running the current release closes all known holes.

14 independent researchers contributed these findings, most of them (6) reported by Luc Huynh from Noventiq RedTeam.

01234567891026.02.2015Today26.02.20159.8Gravityforms <= 1.8.19 - Arbitrary File Upload CVSS 9.8 · 26.02.201517.03.20159.1Gravityforms <= 1.9.3.5 - SQL Injection CVSS 9.1 · 17.03.201520.04.20155.4Gravityforms <= 1.9.6 - Cross-Site Scripting CVSS 5.4 · 20.04.201501.03.20164.7Gravityforms <= 1.9.15.11 - Cross-Site Scripting CVSS 4.7 · 01.03.201607.09.20165.4Gravity Forms <= 2.0.6.5 - Cross-Site Scripting CVSS 5.4 · 07.09.201608.05.20197.5Gravityforms <= 2.4.8 - Information Exposure CVSS 7.5 · 08.05.201929.05.20239.8Gravity Forms <= 2.7.3 - Unauthenticated PHP Object Injection CVSS 9.8 · 29.05.202321.06.20236.1Gravity Forms <= 2.7.4 - Reflected Cross-Site Scripting CVSS 6.1 · 21.06.202316.01.20257.2GravityForms <= 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'alt' parameter CVSS 7.2 · 16.01.20255.4GravityForms 2.9.0.1 - 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'style_settings' parameter CVSS 5.4 · 16.01.202506.11.20259.8Gravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via 'copy_post_image' CVSS 9.8 · 06.11.202517.11.20258.1Gravity Forms <= 2.9.21.1 - Unauthenticated Arbitrary File Upload via Legacy Chunked Upload CVSS 8.1 · 17.11.202503.12.20259.8Gravity Forms <= 2.9.23.0 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 03.12.202510.03.20266.4Gravity Forms <= 2.9.28.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title CVSS 6.4 · 10.03.202607.04.20264.7Gravity Forms <= 2.9.30 - Reflected Cross-Site Scripting via 'form_ids' Parameter CVSS 4.7 · 07.04.20266.1Gravity Forms <= 2.9.30 - Unauthenticated Stored Cross-Site Scripting via Credit Card 'Card Type' Sub-Field CVSS 6.1 · 07.04.202601.05.20267.2Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Single Product Field Inside Repeater CVSS 7.2 · 01.05.20267.2Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Hidden Product Field in Repeater CVSS 7.2 · 01.05.20267.2Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Product Option CVSS 7.2 · 01.05.20267.2Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Calculation Product Field in Repeater CVSS 7.2 · 01.05.20267.2Gravity Forms <= 2.9.30 - Unauthenticated Stored Cross-Site Scripting via Consent Field Hidden Input CVSS 7.2 · 01.05.202601.06.20269.1Gravity Forms <= 2.10.0.1 - Unauthenticated Arbitrary File Deletion CVSS 9.1 · 01.06.202615.07.20267.5Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter CVSS 7.5 · 15.07.202601.09.20268.1Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload via State/Chunk Hash Confusion CVSS 8.1 · 01.09.202604.09.20267.2Gravity Forms <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via Post Body Field Value CVSS 7.2 · 04.09.2026

Strategic Overview

Avg CVSSHigh
7.3/ 10
Patch Coverage100%
Open

0

Fixed

25

Get automatic notifications for all Gravity Forms vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2025-13407

Gravity Forms <= 2.9.23.0 - Unauthenticated Arbitrary File Upload

Read the full analysis

Vulnerability Records

25 records
2026-09-04 18:06CVE-2026-16649
7.2
High
darooYes
2026-09-01 01:18CVE-2026-19513
8.1
High
Alex ThomasYes
2026-07-15 06:20CVE-2026-12997
7.5
High
darooYes
2026-06-01 00:00CVE-2026-48866
9.1
Critical
darooYes
2026-05-01 00:00CVE-2026-5110
7.2
High
Luc Huynh from Noventiq RedTeamYes
2026-05-01 00:00CVE-2026-5111
7.2
High
Luc Huynh from Noventiq RedTeamYes
2026-05-01 00:00CVE-2026-5109
7.2
High
Luc Huynh from Noventiq RedTeamYes
2026-05-01 00:00CVE-2026-5112
7.2
High
Luc Huynh from Noventiq RedTeamYes
2026-05-01 00:00CVE-2026-5113
7.2
High
Luc Huynh from Noventiq RedTeamYes
2026-04-07 10:47CVE-2026-4394
6.1
Medium
Luc Huynh from Noventiq RedTeamYes
Showing 1–10 of 25 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C