CVE-2024-31857: Incsub Forminator

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain user information etc. and alter the page contents on the user's web browser.

Affected products

  • Incsub Forminator: before 1.15.4 (fixed in 1.15.4)

Published 2024-04-23. Last modified 2026-06-17.