Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.27% | — | Digitaldonkey Multilang Contact FormAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitaldonkey Multilang Contact Form multilang-contact-form allows Reflected XSS.This issue affects Multilang Contact Form: from n/a through <= 1.5. | |
| Aplazada | Media (6.5) | 0.23% | — | Olaf Lederer Fws-ajax-contact-formAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer Ajax Contact Form fws-ajax-contact-form allows Stored XSS.This issue affects Ajax Contact Form: from n/a through <= 1.4.1. | |
| Aplazada | Media (6.1) | 0.36% | — | Contact Form 7 Redirect Thank YOU PageAI | 15/1/2025 | 17/6/2026 | The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Media (6.1) | 0.36% | — | Edmonparker Contact Form Master | 11/1/2025 | 17/6/2026 | The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.6) | 0.47% | — | Penguinarts Contact Form 7 Database Cfdb7AI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in penguinarts Contact Form 7 Database – CFDB7 advanced-cf7-database allows SQL Injection.This issue affects Contact Form 7 Database – CFDB7: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.46% | — | Design FOR Contact Form 7 Style CF7 WOW StylerAI | 7/1/2025 | 17/6/2026 | The The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.… | |
| Aplazada | Alta (7.5) | 0.52% | — | Themefic Ultimate Addons FOR Contact Form 7AI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through <= 3.2.6. | |
| Aplazada | Media (6.4) | 0.30% | — | Mightyforms Contact Form Survey AND Form BuilderAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in mightyforms Contact Form, Survey & Form Builder – MightyForms mightyforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form, Survey & Form Builder – MightyForms: from n/a through <= 1.3.9. | |
| Aplazada | Media (4.3) | 0.26% | — | Dbar Productions Member Directory AND Contact FormAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in DBAR Productions Member Directory and Contact Form pta-member-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Member Directory and Contact Form: from n/a through <= 1.7.0. | |
| Aplazada | Media (4.3) | 0.15% | — | Sevenspark Contact Form 7 Dynamic Text ExtensionAI | 31/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sevenspark Contact Form 7 – Dynamic Text Extension contact-form-7-dynamic-text-extension allows Cross Site Request Forgery.This issue affects Contact Form 7 – Dynamic Text Extension: from n/a through <= 5.0.1. | |
| Aplazada | Media (5.3) | 0.39% | — | Accept Authorize NET Payments Using Contact Form 7AI | 18/12/2024 | 17/6/2026 | The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2 via the cf7adn-info.php file. This makes it possible for unauthenticated attackers to extract configuration data which can be used to aid in other attacks. | |
| Aplazada | Alta (7.6) | 0.52% | — | Tsjippy Mollie FOR Contact Form 7AI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tsjippy Mollie for Contact Form 7 cf7-mollie allows Blind SQL Injection.This issue affects Mollie for Contact Form 7: from n/a through <= 5.0.0. | |
| Analizada | Media (6.1) | 0.36% | — | Fluentforms Contact Form | 14/12/2024 | 17/6/2026 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.35% | — | Thehowarde Connect-contact-form-7-to-constant-contactAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thehowarde Connect Contact Form 7 to Constant Contact connect-contact-form-7-to-constant-contact-v3 allows Reflected XSS.This issue affects Connect Contact Form 7 to Constant Contact: from n/a through <= 1.4. | |
| Aplazada | Media (5.3) | 0.70% | — | Guido VS Contact FormAI | 13/12/2024 | 17/6/2026 | Weak Authentication vulnerability in Guido VS Contact Form allows Authentication Abuse.This issue affects VS Contact Form: from n/a through 14.0. | |
| Modificada | Alta (8.8) | 0.56% | — | Cimatti Wordpress Contact Forms | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Cimatti Consulting Contact Forms by Cimatti allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Forms by Cimatti: from n/a through 1.5.7. | |
| Aplazada | Media (4.3) | 0.47% | — | Constantcontact Constant Contact FormsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Constant Contact Constant Contact Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Constant Contact Forms: from n/a through 2.0.3. | |
| Aplazada | Alta (7.5) | 0.79% | — | Webcodin WCP Contact FormAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0. | |
| Aplazada | Media (4.3) | 0.51% | — | Webcodin WCP Contact FormAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0. | |
| Analizada | Media (5.3) | 0.52% | — | Zealousweb Accept Stripe Payments Using Contact Form 7 | 12/12/2024 | 17/6/2026 | The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via the cf7sa-info.php file that returns phpinfo() data. This makes it possible for unauthenticated attackers to extract configuration information that can be leveraged… | |
| Aplazada | Media (4.3) | 0.37% | — | Custom Skins Contact Form 7AI | 12/12/2024 | 17/6/2026 | The Custom Skins Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'cf7cs_action_callback' function in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (6.3) | 0.38% | — | Kofimokome Message Filter FOR Contact Form 7AI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter.This issue affects Message Filter for Contact Form 7: from n/a through <= 1.6.3. | |
| Modificada | Crítica (9.8) | 0.62% | — | Wpmet Metform Elementor Contact Form Builder | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Roxnor Metform metform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Metform: from n/a through <= 3.4.0. | |
| Aplazada | Media (4.3) | 0.48% | — | Itpathsolutions Contact Form TO ANY APIAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in IT Path Solutions Contact Form to Any API allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form to Any API: from n/a through 1.1.6. | |
| Aplazada | Media (4.3) | 0.34% | — | Jules Colle Conditional Fields FOR Contact Form 7AI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Jules Colle Conditional Fields for Contact Form 7 cf7-conditional-fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conditional Fields for Contact Form 7: from n/a through <= 2.4.1. |