Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

1178 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.19%—Fluentforms Fluent Forms PRO ADD ON PackAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions.
AplazadaAlta (7.1)0.25%—Reputeinfosystems ArformsAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.
AplazadaAlta (7.1)0.24%—Rednao Smart FormsAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Smart Forms <= 2.6.104 versions.
AplazadaMedia (5.3)0.18%—Wpmanageninja Fluent Forms PROAI5/10/20266/10/2026
Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13.
AplazadaAlta (8.1)0.52%—Ninjaforms Ninja Forms File UploadsAI2/10/20262/10/2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used…
AplazadaAlta (7.2)0.29%—Ninjaforms Ninja FormsAI2/10/20263/10/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaAlta (8.8)0.30%—Super-forms Super FormsAI2/10/20263/10/2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value…
AplazadaCrítica (9.1)0.88%—Super-forms Super FormsAI2/10/20262/10/2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive…
AplazadaAlta (8.1)0.54%—Super-forms Super FormsAI1/10/20263/10/2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super…
AplazadaCrítica (9.8)0.29%—Super-forms Super FormsAI1/10/20261/10/2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that…
En análisisAlta (7.2)0.25%—Kiteworks Advanced FormsAI30/9/20261/10/2026
A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions.
En análisisAlta (7.1)0.24%—Kiteworks Secure Data FormsAI30/9/20261/10/2026
A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an…
En análisisAlta (7.5)0.32%—Kiteworks Secure Data FormsAI30/9/20261/10/2026
Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other…
Pendiente de análisisBaja (1.2)0.30%—Wikimedia Page FormsAI30/9/202630/9/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43.
AplazadaAlta (7.1)0.18%—HappyformsAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions.
AplazadaAlta (8.8)0.48%—Quantumcloud Conversational Forms FOR ChatbotAI30/9/202630/9/2026
Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.
AplazadaAlta (7.1)0.18%—Ninjaforms Ninja FormsAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
En análisisCrítica (9.5)0.32%—Balbooa FormsAI29/9/202630/9/2026
Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component…
En análisisAlta (8.9)0.37%—Balbooa FormsAI29/9/202630/9/2026
Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the…
En análisisAlta (8.6)0.32%—Balbooa FormsAI29/9/202630/9/2026
Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A…
En análisisMedia (6.9)0.37%—Balbooa FormsAI29/9/202630/9/2026
Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and display names are trusted directly, introducing potential cross-session claiming, metadata…
En análisisMedia (6.9)0.29%—Balbooa FormsAI29/9/202630/9/2026
Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session…
AplazadaMedia (6.5)0.18%—Wpforms LiteAI28/9/202628/9/2026
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public…
AplazadaAlta (7.2)0.24%—Repeater Fields FOR Elementor FormsAI25/9/202625/9/2026
The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AplazadaMedia (6.1)0.27%—WpformsAI25/9/202625/9/2026
The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'page_title' POST Parameter via {page_title} Smart Tag in all versions up to, and including, 2.0.2 due to insufficient input sanitization and…