PT-2026-60257 · Gravity Forms+1 · Gravity Forms

·

CVE-2026-12997

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gravity Forms versions prior to 2.10.5
Description An issue exists where unauthenticated attackers can read arbitrary files from the server that may contain sensitive information. This occurs when a targeted form is publicly accessible and does not enforce login, allowing the attacker to access the process send resume link endpoint. By manipulating the gform uploaded files parameter, the attacker can specify a recipient email address to receive the retrieved file as a notification attachment. Directory Traversal is a method used to access files and directories that are stored outside the web root folder.
Recommendations Update Gravity Forms to version 2.10.5 or later. Restrict access to the process send resume link endpoint or ensure that forms requiring file handling enforce user login.

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12997

Affected Products

Gravity Forms