17 Total CVEs
17 AI Analyzed
0 CISA KEV
15 Critical

Profile

0% ended up actively exploited 0 of 17 added to CISA KEV
88% rated critical (CVSS 9.0+) 15 critical, 2 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

17 CVEs in the last 12 months

Products

  • Contact Form 7, WPForms, Elementor, Ninja Forms Integration1
  • Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms1
  • Integration for Contact Form 7 HubSpot1
  • Integration for Salesforce1
  • Integration for Contact Form 7 and Constant Contact1
  • WP Zendesk1
  • Integration for Keap/infusionsoft1
  • WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms1

8 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-17 of 17 CVEs
CVE-2026-9691
Analyzed
9.8
CRM Perks Contact Form 7, WPForms, Elementor, Ninja Forms Integration

An unauthenticated PHP Object Injection vulnerability (CWE-502) affects the Integration for ActiveCampaign and various form plugins, potentially allow...

2026-06-16
CVE-2026-49765
Analyzed
9.8
CRM Perks Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms

The Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress suffers from unauthenticated PHP Object Injecti...

2026-06-16
CVE-2026-49763
Analyzed
9.8
CRM Perks Integration for Contact Form 7 HubSpot

The Integration for Contact Form 7 HubSpot plugin for WordPress is vulnerable to unauthenticated PHP Object Injection, potentially allowing remote cod...

2026-06-16
CVE-2026-49109
Analyzed
9.8
CRM Perks Integration for Salesforce

An unauthenticated PHP Object Injection vulnerability in the CRM Perks Integration for Salesforce allows remote attackers to achieve arbitrary code ex...

2026-06-16
CVE-2026-49106
Analyzed
9.8
CRM Perks Integration for Contact Form 7 and Constant Contact

An unauthenticated PHP Object Injection vulnerability exists in the CRM Perks Integration for Contact Form 7 and Constant Contact, enabling potential...

2026-06-16
CVE-2026-49105
Analyzed
9.8
CRM Perks WP Zendesk

An unauthenticated PHP Object Injection vulnerability in the WP Zendesk integration for WordPress allows attackers to execute arbitrary code via deser...

2026-06-16
CVE-2026-49104
Analyzed
9.8
CRM Perks Integration for Keap/infusionsoft

An unauthenticated PHP Object Injection vulnerability in the CRM Perks Integration for Keap/infusionsoft allows remote attackers to perform deserializ...

2026-06-16
CVE-2026-49085
Analyzed
9.8
CRM Perks WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms

An unauthenticated PHP Object Injection vulnerability exists in the WP Insightly integration plugin for various WordPress form builders, allowing pote...

2026-06-16
CVE-2025-68590
Analyzed
9.8
CRM Perks Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Integration for Contact Form 7 HubSpot...

2025-12-25
CVE-2025-60209
Analyzed
8.2
CRM Perks Multiple Products

Deserialization of Untrusted Data vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Object...

2025-10-22
CVE-2025-60180
Analyzed
9.8
CRM Perks Multiple Products

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue aff...

2025-12-19
CVE-2025-60178
Analyzed
9.8
CRM Perks Multiple Products

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection.This issue affects WP Gravity...

2025-12-19
CVE-2025-60174
Analyzed
9.8
CRM Perks Multiple Products

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contact allows Object Injection.This...

2025-12-19
CVE-2025-60151
Analyzed
7.5
CRM Perks Multiple Products

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Phishing

2025-10-22
CVE-2025-60091
Analyzed
9.8
CRM Perks Multiple Products

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects WP...

2025-12-19
CVE-2025-60090
Analyzed
9.8
CRM Perks Multiple Products

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gra...

2025-12-19
CVE-2025-60089
Analyzed
9.8
CRM Perks Multiple Products

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects...

2025-12-19