Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

264 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.82%—Themefic Ultimate Addons FOR Contact Form 79/6/202317/6/2026
The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and including, 3.1.23. This makes it possible for authenticated attackers of any authorization level to append additional SQL queries into already existing queries that can be used to…
ModificadaMedia (5.4)0.40%—Crmperks Contact Form Entries - Contact Form 7 Wpforms AND More28/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CRM Perks Contact Form Entries plugin <= 1.3.0 versions.
ModificadaAlta (8.8)0.26%—Crmperks Integration FOR Contact Form 7 AND Zoho Crm, Bigin26/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin plugin <= 1.2.2 versions.
ModificadaAlta (8.8)0.25%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 724/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.
ModificadaMedia (6.1)0.54%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 717/4/202317/6/2026
The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a…
ModificadaMedia (4.3)0.28%—Hasthemes Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks27/3/202317/6/2026
The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
ModificadaAlta (8.8)0.27%—Voidcoders Void Contact Form 7 Widget FOR Elementor Page Builder13/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions.
ModificadaCrítica (9.8)3.0%💥 PoCCodedropz Drag AND Drop Multiple File Upload - Contact Form 71/3/202317/6/2026
A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack…
ModificadaMedia (5.4)0.56%—Send PDF FOR Contact Form 7 Project Send PDF FOR Contact Form 76/2/202317/6/2026
The Send PDF for Contact Form 7 WordPress plugin before 0.9.9.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege…
ModificadaCrítica (9.8)3.9%—Ciphercoin Contact Form 7 Database Addon21/11/202217/6/2026
The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection
ModificadaMedia (4.3)0.59%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 717/10/202217/6/2026
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.
ModificadaAlta (7.5)0.61%—Redirection-for-contact-form7 Redirection FOR Contact Form 711/10/202217/6/2026
Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional extension (plugin) AccessiBe.
ModificadaMedia (4.8)0.67%—Zealousweb Generate PDF Using Contact Form 726/9/202217/6/2026
The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (6.1)1.5%💥 ExploitContact Form 7 Captcha Project Contact Form 7 Captcha17/7/202217/6/2026
The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
ModificadaMedia (4.3)0.43%—Jquery Validation FOR Contact Form 7 Project Jquery Validation FOR Contact Form 717/7/202217/6/2026
The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change Blog options like default_role, users_can_register via a CSRF attack
ModificadaMedia (6.1)1.6%💥 ExploitRedirection-for-contact-form7 Redirection FOR Contact Form 74/7/202217/6/2026
The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.5)1.1%—Material Design FOR Contact Form 7 Project Material Design FOR Contact Form 74/4/202217/6/2026
The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in user (with roles as low as Subscriber) to set arbitrary options…
ModificadaMedia (5.4)14%💥 ExploitCodedropz Drag AND Drop Multiple File Upload - Contact Form 728/3/202217/6/2026
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue
ModificadaMedia (6.1)0.80%—WKI Idpay FOR Contact Form 714/3/202217/6/2026
The IDPay for Contact Form 7 WordPress plugin through 2.1.2 does not sanitise and escape the idpay_error parameter before outputting it back in the page leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)2.1%💥 ExploitCf7skins Contact Form 7 Skins1/2/202217/6/2026
The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaAlta (8.8)0.54%—Ciphercoin Contact Form 7 Database Addon22/12/202117/6/2026
Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.5.9).
ModificadaMedia (6.1)0.76%—Ciphercoin Contact Form 7 Database Addon22/12/202117/6/2026
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.6.1).
ModificadaAlta (8.8)0.72%—Contact Form 7 Captcha Project Contact Form 7 Captcha23/8/202117/6/2026
The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored Cross-Site Scripting issue.
ModificadaMedia (6.3)0.73%—Querysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s settings, wpcf7r_add_action to add actions to a…
ModificadaMedia (4.3)0.66%—Querysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site.