Basix Nex-Forms vulnerabilities

5 known vulnerabilities affecting basix/nex-forms.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1UNKNOWN1

Vulnerabilities

Page 1 of 1
CVE-2025-69326HIGHCVSS 7.1≤ 9.1.72026-02-20
CVE-2025-69326 [HIGH] CWE-79 CVE-2025-69326: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Reflected XSS.This issue affects NEX-Forms: from n/a through <= 9.1.7.
cvelistv5nvd
CVE-2025-69324HIGHCVSS 7.1≤ 9.1.72026-02-20
CVE-2025-69324 [HIGH] CWE-79 CVE-2025-69324: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Stored XSS.This issue affects NEX-Forms: from n/a through <= 9.1.7.
cvelistv5nvd
CVE-2025-49399UNKNOWN≤ 9.1.32025-08-20
CVE-2025-49399 CWE-352 CVE-2025-49399: Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Cross Site Request Forgery.This issue affects NEX-Forms: from n/a through <= 9.1.3.
cvelistv5nvd
CVE-2024-53808HIGHCVSS 7.2≤ 8.7.82024-12-06
CVE-2024-53808 [HIGH] CWE-89 CVE-2024-53808: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows SQL Injection.This issue affects NEX-Forms: from n/a through <= 8.7.8.
cvelistv5nvd
CVE-2024-47389MEDIUMCVSS 6.1≤ 8.7.32024-10-05
CVE-2024-47389 [MEDIUM] CWE-79 CVE-2024-47389: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Reflected XSS.This issue affects NEX-Forms: from n/a through <= 8.7.3.
cvelistv5nvd