Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
1178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.19% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Reputeinfosystems ArformsAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Rednao Smart FormsAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Smart Forms <= 2.6.104 versions. | |
| Aplazada | Media (5.3) | 0.18% | — | Wpmanageninja Fluent Forms PROAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13. | |
| Aplazada | Alta (8.1) | 0.52% | — | Ninjaforms Ninja Forms File UploadsAI | 2/10/2026 | 2/10/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used… | |
| Aplazada | Alta (7.2) | 0.29% | — | Ninjaforms Ninja FormsAI | 2/10/2026 | 3/10/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.8) | 0.30% | — | Super-forms Super FormsAI | 2/10/2026 | 3/10/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value… | |
| Aplazada | Crítica (9.1) | 0.88% | — | Super-forms Super FormsAI | 2/10/2026 | 2/10/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Aplazada | Alta (8.1) | 0.54% | — | Super-forms Super FormsAI | 1/10/2026 | 3/10/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super… | |
| Aplazada | Crítica (9.8) | 0.29% | — | Super-forms Super FormsAI | 1/10/2026 | 1/10/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that… | |
| En análisis | Alta (7.2) | 0.25% | — | Kiteworks Advanced FormsAI | 30/9/2026 | 1/10/2026 | A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions. | |
| En análisis | Alta (7.1) | 0.24% | — | Kiteworks Secure Data FormsAI | 30/9/2026 | 1/10/2026 | A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an… | |
| En análisis | Alta (7.5) | 0.32% | — | Kiteworks Secure Data FormsAI | 30/9/2026 | 1/10/2026 | Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other… | |
| Pendiente de análisis | Baja (1.2) | 0.30% | — | Wikimedia Page FormsAI | 30/9/2026 | 30/9/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43. | |
| Aplazada | Alta (7.1) | 0.18% | — | HappyformsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions. | |
| Aplazada | Alta (8.8) | 0.48% | — | Quantumcloud Conversational Forms FOR ChatbotAI | 30/9/2026 | 30/9/2026 | Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Ninjaforms Ninja FormsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | |
| En análisis | Crítica (9.5) | 0.32% | — | Balbooa FormsAI | 29/9/2026 | 30/9/2026 | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component… | |
| En análisis | Alta (8.9) | 0.37% | — | Balbooa FormsAI | 29/9/2026 | 30/9/2026 | Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the… | |
| En análisis | Alta (8.6) | 0.32% | — | Balbooa FormsAI | 29/9/2026 | 30/9/2026 | Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A… | |
| En análisis | Media (6.9) | 0.37% | — | Balbooa FormsAI | 29/9/2026 | 30/9/2026 | Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and display names are trusted directly, introducing potential cross-session claiming, metadata… | |
| En análisis | Media (6.9) | 0.29% | — | Balbooa FormsAI | 29/9/2026 | 30/9/2026 | Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session… | |
| Aplazada | Media (6.5) | 0.18% | — | Wpforms LiteAI | 28/9/2026 | 28/9/2026 | The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public… | |
| Aplazada | Alta (7.2) | 0.24% | — | Repeater Fields FOR Elementor FormsAI | 25/9/2026 | 25/9/2026 | The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (6.1) | 0.27% | — | WpformsAI | 25/9/2026 | 25/9/2026 | The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'page_title' POST Parameter via {page_title} Smart Tag in all versions up to, and including, 2.0.2 due to insufficient input sanitization and… |