Known vulnerabilities in the Sureforms plugin
14 security advisories have been published for the Sureforms plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Sureforms - Cross-Site Scripting (XSS) (CVE-2026-7623) MEDIUM
- Sureforms - Security Vulnerability (CVE-2026-11567) MEDIUM
- Sureforms - Cross-Site Scripting (XSS) (CVE-2025-14855) HIGH
- Sureforms - Cross-Site Request Forgery (CSRF) (CVE-2025-12535) MEDIUM
- Sureforms - Information Disclosure (CVE-2025-12536) MEDIUM
- Sureforms - Broken Access Control (CVE-2025-10732) MEDIUM
- Sureforms - Cross-Site Scripting (XSS) (CVE-2025-8282) LOW
- Sureforms - Cross-Site Scripting (XSS) (CVE-2025-5921) MEDIUM
- Sureforms - PHP Object Injection (CVE-2025-6742) HIGH
- Sureforms - Remote Code Execution (CVE-2025-6691) HIGH
- Sureforms - Cross-Site Scripting (XSS) (CVE-2025-3514) LOW
- Sureforms - Cross-Site Scripting (XSS) (CVE-2025-3513) LOW
- Sureforms - Security Vulnerability (CVE-2025-3471) MEDIUM
- Sureforms - Information Disclosure (CVE-2024-12713) MEDIUM