CVE-2024-31077: Incsub Forminator

High severity, CVSS 7.2. EPSS: 30.4% chance of exploitation in the next 30 days.

Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain and alter any information in the database and cause a denial-of-service (DoS) condition.

Affected products

  • Incsub Forminator: before 1.29.3 (fixed in 1.29.3)

Published 2024-04-23. Last modified 2026-06-17.