
CVE-2024-13377 – GravityForms <= 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'alt' parameter
https://notcve.org/view.php?id=CVE-2024-13377
16 Jan 2025 — The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. El complemento Gravity Forms para WordPress es vulnerable a Cross-Site Scripting almacenado a través del parámetro "alt" en todas las versiones... • https://docs.gravityforms.com/gravityforms-change-log • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-2701 – Gravity Forms < 2.7.5 - Reflected XSS
https://notcve.org/view.php?id=CVE-2023-2701
21 Jun 2023 — The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin. The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page... • https://wpscan.com/vulnerability/298fbe34-62c2-4e56-9bdb-90da570c5bbe • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-28782 – WordPress Gravity Forms Plugin <= 2.7.3 is vulnerable to PHP Object Injection
https://notcve.org/view.php?id=CVE-2023-28782
29 May 2023 — Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3. Vulnerabilidad de deserialización de datos no confiables en Rocketgenius Inc. Gravity Forms. Este problema afecta a Gravity Forms: desde n/a hasta 2.7.3. • https://patchstack.com/database/vulnerability/gravityforms/wordpress-gravity-forms-plugin-2-7-3-unauthenticated-php-object-injection-vulnerability?_s_id=cve • CWE-502: Deserialization of Untrusted Data •

CVE-2017-17780 – Clockwork SMS Plugins - Multiple Versions - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2017-17780
18 Dec 2017 — The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2, Booking Calendar - Clockwork SMS 1.0.5, Contact Form 7 - Clockwork SMS 2.3.0, Fast Secure Contact Form - Clockwork SMS 2.1.2, Formidable - Clockwork SMS 1.0.2, Gravity Forms - Clockwork SMS 2.2, and... • https://packetstormsecurity.com/files/145469/Clockwork-SMS-Cross-Site-Scripting.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-18495 – Clockwork SMS Notfications < 2.4.2 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2017-18495
27 Nov 2017 — The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS. El complemento gravity-forms-sms-notifications anterior de 2.4.0 para WordPress tiene XSS. The gravity-forms-sms-notifications plugin before 2.4.2 for WordPress has XSS. • https://wordpress.org/plugins/gravity-forms-sms-notifications/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •