cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forhappyforms happyforms

Direction: descending
Jun 10, 2026

Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms # CVE-2026-49768

CVE, Research URL

CVE-2026-49768

Date
-
Research Description
Happyforms &#8211; Form Builder for WordPress: Drag &amp; Drop Contact Forms, Surveys, Payments &amp; Multipurpose Forms [happyforms] < 1.26.14 CVE-2026-49768
Affected versions
max 1.26.14.
Status
vulnerable
May 17, 2025

Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms # CVE-2024-10054

CVE, Research URL

CVE-2024-10054

Date
May 16, 2025
Research Description
The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 1.26.3.
Status
vulnerable
Sep 02, 2024

Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms # CVE-2024-44063

CVE, Research URL

CVE-2024-44063

Date
Sep 15, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Happyforms allows Stored XSS.This issue affects Happyforms: from n/a through 1.26.0.
Affected versions
max 1.26.1.
Status
vulnerable
Jun 10, 2024
Jun 06, 2024

Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms # CVE-2023-48752

CVE, Research URL

CVE-2023-48752

Date
Nov 30, 2023
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Happyforms Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms allows Reflected XSS.This issue affects Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms: from n/a through 1.25.9.
Affected versions
max 1.25.10.
Status
vulnerable

Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms # CVE-2023-0096

CVE, Research URL

CVE-2023-0096

Date
Feb 07, 2023
Research Description
The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected versions
max 1.22.0.
Status
vulnerable