Known vulnerabilities in the Forms plugin
7 security advisories have been published for the Forms plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Forms - Cross-Site Request Forgery (CSRF) (CVE-2025-2935) MEDIUM
- Forms - Remote Code Execution (CVE-2024-13725) CRITICAL
- Forms - Cross-Site Request Forgery (CSRF) (CVE-2023-7065) MEDIUM
- Forms - Cross-Site Scripting (XSS) (CVE-2023-2488) MEDIUM
- Forms - Cross-Site Scripting (XSS) (CVE-2023-2489) MEDIUM
- Forms - Cross-Site Scripting (XSS) (CVE-2021-24517) MEDIUM
- Forms - Cross-Site Scripting (XSS) (CVE-2021-24505) MEDIUM