SecAlerts
n

nex-forms

Security Risk Profile

33
/100
low

Security Risk Score

Comprehensive risk assessment based on 12 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 12, 2025 to present

12
Total CVEs
3
Critical+High
0
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
5.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
33/100
low
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
0
High
3
Medium
9
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
3

Age Distribution

Common Weaknesses (CWE)

1
XSS
5
2
SQL Injection
3
3
CSRF
1
4
Code Injection
1
5
Infoleak
1

Most Affected Products

1. NEX-Forms Ultimate Forms Plugin for WordPress5
2. NEX-Forms Ultimate Form Builder3
3. NEX-Forms WordPress plugin2
4. Basixonline Nex-forms Wordpress2
5. NEX-Forms NEX-Forms Ultimate Forms Plugin for WordPress1

Recent Vulnerabilities

See more →
CVE-2026-75961
CVSS 4.9medium

NEX-Forms <= 9.3.0 - Authenticated (Administrator+) SQL Injection via 'operator' Key of the 'additional_params' Parameter

Sep 18, 2026🔧 No Patch
CVE-2026-10525
CVSS 6.1medium

NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission

Jul 17, 2026🔧 No Patch
CVE-2026-9017
CVSS 5.3EPSS 0%medium

NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action

Jul 11, 2026🔧 No Patch
CVE-2026-13040
CVSS 7.2high

NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter

Jul 3, 2026🔧 No Patch
CVE-2026-12142
CVSS 7.2high

NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter

Jul 1, 2026🔧 No Patch
CVE-2026-12404
CVSS 5.3medium

NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class

Jun 27, 2026🔧 No Patch
CVE-2026-7046
CVSS 4.9EPSS 0%medium

NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.12 - Authenticated (Administrator+) SQL Injection via 'table' Parameter

May 15, 2026🔧 No Patch
CVE-2026-5063
CVSS 7.2high

NEX-Forms <= 9.1.11 - Unauthenticated Stored Cross-Site Scripting via POST Parameter Key Names

May 3, 2026🔧 No Patch
CVE-2025-10185
CVSS 4.9medium

NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.6 - Authenticated (Admin+) SQL Injection

Oct 11, 2025🔧 No Patch
CVE-2025-4208
CVSS 6.3EPSS 0%medium

NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Limited Code Execution via get_table_records Function

May 8, 2025🔧 No Patch

Monitor nex-forms in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.