Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
264 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.0% | — | Querysol Redirection FOR Contact Form 7 | 14/5/2021 | 17/6/2026 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects. | |
| Modificada | Media (6.5) | 0.83% | — | Querysol Redirection FOR Contact Form 7 | 14/5/2021 | 17/6/2026 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository. | |
| Modificada | Alta (7.5) | 7.4% | 💥 Exploit | Querysol Redirection FOR Contact Form 7 | 14/5/2021 | 17/6/2026 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function. | |
| Modificada | Alta (8.8) | 0.59% | — | Rocklobster Contact Form 7 | 5/4/2021 | 17/6/2026 | Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style WordPress plugin through 3.1.9. If an attacker successfully tricked a site’s administrator into clicking a link or… | |
| Modificada | Alta (7.8) | 1.2% | — | Ciphercoin Contact Form 7 Database Addon | 18/3/2021 | 17/6/2026 | Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files. | |
| Modificada | Crítica (10) | 89% | 💥 PoC | Rocklobster Contact Form 7 | 17/12/2020 | 17/6/2026 | The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters. | |
| Modificada | Crítica (9.8) | 79% | 💥 Exploit | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 8/6/2020 | 17/6/2026 | The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file. | |
| Modificada | Media (5.4) | 0.71% | — | Contact-form-7-datepicker Project Contact-form-7-datepicker | 7/4/2020 | 17/6/2026 | Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minimal permissions to save arbitrary JavaScript to the plugin's settings via the unprotected wp_ajax_cf7dp_save_settings AJAX action and the ui_theme parameter. If an administrator creates or modifies a… | |
| Modificada | Crítica (9.8) | 2.0% | — | Rocklobster Contact Form 7 | 22/8/2019 | 17/6/2026 | The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type. | |
| Modificada | Media (6.1) | 0.92% | — | Mediaburst Contact Form 7 - Clockwork SMS | 13/8/2019 | 17/6/2026 | The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS. | |
| Modificada | Crítica (9.6) | 7.3% | 💥 Exploit | Contact-form-7-to-database-extension Project Contact-form-7-to-database-extension | 4/4/2018 | 17/6/2026 | CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form. | |
| Modificada | Media (6.1) | 0.95% | — | Mediaburst Booking Calendar SMSMediaburst Clockwork SMS NotficationsMediaburst Contact Form 7 SMSMediaburst Fast Secure Contact Form SMS+4 | 20/12/2017 | 17/6/2026 | The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2,… | |
| Modificada | Media (4.3) | 1.6% | — | Contactus Contact Form 7 Integrations | 26/9/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in includes/toAdmin.php in Contact Form 7 Integrations plugin 1.0 through 1.3.10 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) uE or (2) uC parameter. | |
| Modificada | Media (5) | 3.1% | — | Rocklobster Contact Form 7 | 14/3/2014 | 17/6/2026 | Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter. |