SecAlerts
s

sureforms

Security Risk Profile

34
/100
low

Security Risk Score

Comprehensive risk assessment based on 13 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 8, 2025 to present

13
Total CVEs
2
Critical+High
0
Exploited
2
Unpatched

Threat Assessment

Avg CVSS
5.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
34/100
low
📈 1 in Last 30 Days

Severity Distribution

Critical
0
High
2
Medium
8
Low
3

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
5

Age Distribution

Common Weaknesses (CWE)

1
XSS
5
2
CSRF
1

Most Affected Products

1. Brainstormforce Sureforms Wordpress23
2. SureForms SureForms4
3. SureForms Drag and Drop Form Builder for WordPress3
4. SureForms Drag and Drop Form Builder2
5. SureForms WordPress plugin2

Recent Vulnerabilities

See more →
CVE-2026-7623
CVSS 6.4medium

SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute

Aug 1, 2026🔧 No Patch
CVE-2025-12535
CVSS 5.3medium

SureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution

Nov 19, 2025🔧 No Patch
CVE-2025-12536
CVSS 5.3medium

SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure

Nov 13, 2025🔧 No Patch
CVE-2025-10732
CVSS 4.3medium

SureForms – Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authenticated (Contributor+) Information Disclosure

Oct 14, 2025🔧 No Patch
CVE-2025-8282
CVSS 3.5low

SureForms < 1.9.1 - Admin+ Stored XSS

Sep 23, 2025🔧 No Patch
CVE-2025-10489
CVSS 4.3medium

SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form Creation

Sep 20, 2025🔧 No Patch
CVE-2025-5921
CVSS 5.8medium

SureForms < 1.7.2 - Reflected XSS

Aug 1, 2025🔧 No Patch
CVE-2025-6691
CVSS 8.1EPSS 0%high

SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion

Jul 9, 2025🔧 No Patch
CVE-2025-6742
CVSS 7.5EPSS 0%high

SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion

Jul 9, 2025🔧 No Patch
CVE-2025-3514
CVSS 3.5EPSS 0%low

SureForms < 1.4.4 - Admin+ Stored XSS

May 2, 2025🔧 No Patch

Monitor sureforms in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

sureforms Security Vulnerabilities & Risk Score | 13 CVEs | SecAlerts - SecAlerts