Software intelligence
Important: Happyforms appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works
Tracked advisories
7
Latest advisory
9 July 2026
CISA KEV matches
0
In this WordPress feed
WordPress slug
happyforms
Plugin
This catalog lists 7 known advisories affecting Happyforms. The most recent was published on 9 July 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.
HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Published 9 July 2026
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms <= 1.26.13 - Unauthenticated PHP Object Injection
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Published 4 June 2026
Happyforms <= 1.26.2 - Authenticated (Admin+) Stored Cross-Site Scripting
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 20 November 2024
Known Happyforms advisories published by month.
CVE-2025-11977 · Published 9 July 2026
Affected versions: ≤ 1.26.12
CVE-2026-49768 · Published 4 June 2026
Affected versions: ≤ 1.26.13
CVE-2024-10054 · Published 20 November 2024
Affected versions: ≤ 1.26.2
CVE-2024-44063 · Published 29 August 2024
Affected versions: ≤ 1.26.0
CVE-2024-23521 · Published 31 January 2024
Affected versions: ≤ 1.25.10
CVE-2023-48752 · Published 27 November 2023
Affected versions: ≤ 1.25.9
CVE-2023-0096 · Published 13 January 2023
Affected versions: ≤ 1.21.1
SiteRespond Defence matches your installed Happyforms version against this catalog when the Defence plugin is connected to your WordPress site.