Pricing
Case studies
Login
Start trial
Gravity Forms
N/A
Developer
N/A
Latest version
N/A
Installations
N/A
Last updated
WordPress Plugin
No VDP
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
13 patched
7 Mitigation rules
Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title vulnerability
<= 2.9.28
12/03/2026
WordPress GravityForms plugin 2.9.0.1 - 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'style_settings' parameter vulnerability
2.9.0.1-2.9.1.3
31/12/2025
Unauthenticated Arbitrary File Upload vulnerability
< 2.9.23.1
25/12/2025
Unauthenticated Arbitrary File Upload via Legacy Chunked Upload vulnerability
<= 2.9.21.1
17/11/2025
Unauthenticated Arbitrary File Upload via 'copy_post_image' vulnerability
<= 2.9.20
07/11/2025
Unauthenticated Stored Cross-Site Scripting via 'alt' parameter vulnerability
<= 2.9.1.3
16/01/2025
Reflected XSS vulnerability
< 2.7.5
26/06/2023
Unauthenticated PHP Object Injection vulnerability
<= 2.7.3
29/05/2023
XSS
<= 2.0.6.5
13/10/2016
Arbitrary File Upload
<= 1.8.19
17/06/2016
Authenticated Reflected XSS
<= 1.9.15.11
01/03/2016
Cross Site Scripting
<= 1.9.6
20/04/2015
SQL Injection
<= 1.9.3.5
17/03/2015