CVE-2023-28782

HIGH

Rocketgenius Inc. Gravity Forms <2.7.3 - Deserialization

Title source: llm
STIX 2.1

Description

Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.

Scores

CVSS v3 8.3
EPSS 0.0062
EPSS Percentile 44.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Details

CWE
CWE-502
Status published
Products (2)
gravityforms/gravity_forms < 2.7.4
Rocketgenius Inc./Gravity Forms < 2.7.3
Published Dec 20, 2023
Tracked Since Feb 18, 2026