← WordPress Vulnerabilities
WordPress security by component

Happyforms

Happyforms is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: happyforms

CVE-2026-49768: Happyforms: Code execution

Happyforms is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 1.26.13.

PublishedJun 15, 2026
Known safe version1.26.14
Safe version
Jun 15, 2026 CVE-2026-49768
Happyforms: Code execution
Happyforms is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 1.26.13.
1.26.14
CVE9.8
NVDPending
May 15, 2025 CVE-2024-10054
Happyforms: Cross-site scripting
Happyforms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Sep 15, 2024 CVE-2024-44063
Happyforms: Cross-site scripting
Happyforms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 11, 2024 CVE-2024-23521
Happyforms: A security weakness
Happyforms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Nov 30, 2023 CVE-2023-48752
Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms: Cross-site scripting
Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Feb 06, 2023 CVE-2023-0096
Happyforms: Cross-site scripting
Happyforms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4