CVE-2025-31551: Salesmate.io Salesmate Add-On For Gravity Forms

Critical severity, CVSS 9.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salesmate.io Salesmate Add-On for Gravity Forms gf-salesmate-add-on allows SQL Injection.This issue affects Salesmate Add-On for Gravity Forms: from n/a through <= 2.0.3.

Affected products

  • Salesmate.io Salesmate Add-On For Gravity Forms: up to and including 2.0.3

Published 2025-04-01. Last modified 2026-06-17.