Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

264 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.0%—Querysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects.
ModificadaMedia (6.5)0.83%—Querysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository.
ModificadaAlta (7.5)7.4%💥 ExploitQuerysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.
ModificadaAlta (8.8)0.59%—Rocklobster Contact Form 75/4/202117/6/2026
Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style WordPress plugin through 3.1.9. If an attacker successfully tricked a site’s administrator into clicking a link or…
ModificadaAlta (7.8)1.2%—Ciphercoin Contact Form 7 Database Addon18/3/202117/6/2026
Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.
ModificadaCrítica (10)89%💥 PoCRocklobster Contact Form 717/12/202017/6/2026
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
ModificadaCrítica (9.8)79%💥 ExploitCodedropz Drag AND Drop Multiple File Upload - Contact Form 78/6/202017/6/2026
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
ModificadaMedia (5.4)0.71%—Contact-form-7-datepicker Project Contact-form-7-datepicker7/4/202017/6/2026
Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minimal permissions to save arbitrary JavaScript to the plugin's settings via the unprotected wp_ajax_cf7dp_save_settings AJAX action and the ui_theme parameter. If an administrator creates or modifies a…
ModificadaCrítica (9.8)2.0%—Rocklobster Contact Form 722/8/201917/6/2026
The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.
ModificadaMedia (6.1)0.92%—Mediaburst Contact Form 7 - Clockwork SMS13/8/201917/6/2026
The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS.
ModificadaCrítica (9.6)7.3%💥 ExploitContact-form-7-to-database-extension Project Contact-form-7-to-database-extension4/4/201817/6/2026
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.
ModificadaMedia (6.1)0.95%—Mediaburst Booking Calendar SMSMediaburst Clockwork SMS NotficationsMediaburst Contact Form 7 SMSMediaburst Fast Secure Contact Form SMS+420/12/201717/6/2026
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2,…
ModificadaMedia (4.3)1.6%—Contactus Contact Form 7 Integrations26/9/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in includes/toAdmin.php in Contact Form 7 Integrations plugin 1.0 through 1.3.10 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) uE or (2) uC parameter.
ModificadaMedia (5)3.1%—Rocklobster Contact Form 714/3/201417/6/2026
Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.
Orbitaley — Vulnerabilidades