Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

289 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.18%—Wpmanageninja Fluent Forms PROAI5/10/20266/10/2026
Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13.
AplazadaAlta (8.1)0.52%—Ninjaforms Ninja Forms File UploadsAI2/10/20262/10/2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used…
AplazadaAlta (7.2)0.29%—Ninjaforms Ninja FormsAI2/10/20263/10/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaAlta (7.1)0.18%—Ninjaforms Ninja FormsAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
AplazadaAlta (7.1)0.18%—Ninjaforms Ninja FormsAI23/9/202623/9/2026
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
AplazadaMedia (5.4)0.23%—Wpmanageninja Fluent SupportAI23/9/202623/9/2026
Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.
AplazadaMedia (5.6)0.17%—Wpmanageninja Ninja TablesAI23/9/202623/9/2026
The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table rows which, in a non-default configuration, allows unauthenticated users to have arbitrary shortcodes executed on a public page, and to permanently break that page, by submitting an ordinary form entry.
AplazadaAlta (7.2)0.41%—Ninjaforms Ninja FormsAI22/9/202622/9/2026
Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.
AplazadaAlta (8.8)0.35%—Ninjaforms Ninja FormsAI22/9/202622/9/2026
The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the…
AplazadaAlta (7.5)0.30%—Ninjaforms Ninja FormsAI22/9/202622/9/2026
The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme,…
AplazadaMedia (5.4)0.24%—Ninjateam FilebirdAI18/9/202619/9/2026
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 6.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.3)0.16%—Wpmanageninja FluentauthAI17/9/202619/9/2026
Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.
AplazadaMedia (6.4)0.26%—Ninja Forms Scheduled ExportsAI10/9/202611/9/2026
The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Parameters (interval, format, emailTo) in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.6)0.66%—Ninjaforms Ninja FormsAI9/9/20269/9/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP…
AplazadaMedia (4.8)0.24%—Ninjaforms Ninja FormsAI6/9/20268/9/2026
The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.
AplazadaMedia (4.3)0.16%—Ninja Forms Save ProgressAI5/9/20268/9/2026
The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaAlta (7.2)0.25%—Ninjaforms Ninja FormsAI5/9/20268/9/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaAlta (7.5)0.53%—Invoiceninja Invoice NinjaAI4/9/20269/9/2026
An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components
AplazadaMedia (5.9)0.23%—Thedotstore Ninja FormsAI4/9/20268/9/2026
The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2…
AplazadaAlta (7.1)0.25%—Ninjaforms File Uploads ExtensionAI3/9/20265/9/2026
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
AplazadaAlta (8.8)0.46%—Ninjaforms Ninja Forms - Layout & StylesAI2/9/20263/9/2026
Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
AplazadaBaja (2.1)0.35%—Invoiceninja Invoice NinjaAI1/9/20262/9/2026
A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability affects the function Purify::isHostSafe of the file app/Services/Pdf/Purify.php of the component invoices Endpoint. The manipulation of the argument notes leads to server-side request forgery. It is possible to…
AplazadaBaja (2.1)0.38%—Invoiceninja Invoice NinjaAI1/9/20261/9/2026
A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the argument vendor_contact can lead to authorization bypass. The attack may be performed from remote. The…
AplazadaCrítica (9.3)0.65%—Ninja Tables PROAI13/8/20269/9/2026
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent…
AplazadaBaja (1.9)0.17%—Aktsmm Skill-ninja-mcp-serverAI9/8/202612/8/2026
A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads to path traversal. The attack needs to be performed locally. Upgrading to…
Orbitaley — Vulnerabilidades