Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
1177 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.28% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 1/4/2026 | 17/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Crítica (9.8) | 4.4% | 💥 Exploit | Everest Forms PROAI | 31/3/2026 | 17/6/2026 | The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field values into a PHP code string without proper escaping before… | |
| Aplazada | Media (6.5) | 0.22% | — | Ninjaforms Ninja FormsAI | 28/3/2026 | 17/6/2026 | The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback function for the admin_enqueue_scripts action handler in blocks/bootstrap.php. This makes it possible for authenticated… | |
| Aplazada | Alta (7.5) | 1.2% | 💥 Exploit | Brainstormforce SureformsAI | 28/3/2026 | 17/6/2026 | The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.5.2. This is due to the create_payment_intent() function performing a payment validation solely based on the value of a user-controlled parameter.… | |
| Aplazada | Alta (8.8) | 0.43% | — | Boldgrid WeformsAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects weForms: from n/a through <= 1.6.26. | |
| Aplazada | Media (6.5) | 0.23% | — | Contact Form BY WpformsAI | 25/3/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Retrieve Embedded Sensitive Data.This issue affects Contact Form by WPForms: from n/a through <= 1.9.8.7. | |
| Aplazada | Alta (7.5) | 0.38% | — | Loopus WP Cost Estimation AND Payment Forms BuilderAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in loopus WP Cost Estimation & Payment Forms Builder WP_Estimation_Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through < 10.3.0. | |
| Aplazada | Media (6.4) | 0.24% | — | Integration With Hubspot FormsAI | 21/3/2026 | 17/6/2026 | The Integration with Hubspot Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hubspotform' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.6) | 0.27% | — | Reputeinfosystems ArformsAI | 21/3/2026 | 17/6/2026 | The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This… | |
| Aplazada | Crítica (9.8) | 4.4% | 💥 Exploit | Kaliforms Kali FormsAI | 20/3/2026 | 17/6/2026 | The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder storage, combined with the use of 'call_user_func' on… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpeverest Everest Forms PROAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest Forms Pro allows Stored XSS.This issue affects Everest Forms Pro: from n/a through 1.9.10. | |
| Aplazada | Media (4.3) | 0.21% | — | NEX FormsAI | 16/3/2026 | 17/6/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_license() function in all versions up to, and including, 9.1.9. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Alta (7.5) | 0.27% | — | NEX FormsAI | 16/3/2026 | 17/6/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.1.9 via the submit_nex_form() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to to… | |
| Aplazada | Media (4.3) | 0.27% | — | Contact Form BY WpformsAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through <= 1.9.9.3. | |
| Aplazada | Alta (7.5) | 0.51% | — | Strategy11 Formidable FormsAI | 13/3/2026 | 17/6/2026 | The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`) marking payment records as complete based solely on the Stripe PaymentIntent status without… | |
| Aplazada | Media (5.3) | 0.44% | — | Strategy11 Formidable FormsAI | 13/3/2026 | 17/6/2026 | The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all versions up to, and including, 6.28. This is due to the `frm_strp_amount` AJAX handler (`update_intent_ajax`) overwriting the global `$_POST` data with attacker-controlled JSON input and then using… | |
| Aplazada | Alta (8.2) | 0.43% | — | Google FirebaseAIWeb3formsAI | 12/3/2026 | 17/6/2026 | NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. Prior to 2.0.0, a security vulnerability was identified where Firebase and Web3Forms API keys were exposed. An attacker could use these keys to interact with backend services without authentication,… | |
| Analizada | Media (6.5) | 0.34% | — | Maykinmedia Open Forms | 11/3/2026 | 17/6/2026 | Open Forms allows users create and publish smart forms. Prior to 3.3.13 and 3.4.5, to be able to cosign, the cosigner receives an e-mail with instructions or a deep-link to start the cosign flow. The submission reference is communicated so that the user can retrieve the submission to be cosigned. Attackers can guess a… | |
| Aplazada | Media (6.4) | 0.26% | — | Gravityforms Gravity FormsAI | 11/3/2026 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a compound failure involving missing authorization on the `create_from_template` AJAX endpoint (allowing any authenticated user to create forms), insufficient input… | |
| Aplazada | Media (6.4) | 0.38% | — | Weformspro WeformsAI | 11/3/2026 | 17/6/2026 | The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API entry submission endpoint in all versions up to, and including, 1.6.27. This is due to inconsistent input sanitization between the frontend AJAX handler and the REST API endpoint. When entries are submitted via the REST API… | |
| Aplazada | Media (6.8) | 0.20% | — | Gutena FormsAI | 11/3/2026 | 17/6/2026 | The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register). | |
| Aplazada | Media (6.5) | 0.37% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 5/3/2026 | 17/6/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.17. This is due to the `deleteFile()` method in the `Uploader` class lacking nonce verification and capability checks. The AJAX action is registered via `addPublicAjaxAction()` which… | |
| Aplazada | Alta (7.2) | 0.27% | — | Fluentforms Fluent Forms PROAI | 5/3/2026 | 17/6/2026 | The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_save_data` AJAX action in all versions up to, and including, 6.1.17. This is due to the draft form submission endpoint being publicly accessible without authentication or nonce verification, combined… | |
| Aplazada | Media (6.5) | 0.24% | — | Gutena FormsAI | 4/3/2026 | 17/6/2026 | The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization within the save_gutena_forms_schema() function in all versions up to, and including, 1.6.0. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.14% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 27/2/2026 | 17/6/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (`disable_ipn_verification` defaults to `'yes'` in… |