Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.14% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 27/2/2026 | 17/6/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (`disable_ipn_verification` defaults to `'yes'` in… | |
| Aplazada | Media (6.5) | 0.26% | — | Add-ons.org PDF FOR Elementor FormsAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through <= 6.3.1. | |
| Aplazada | Alta (7.1) | 0.19% | — | Basixonline Nex-formsAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Reflected XSS.This issue affects NEX-Forms: from n/a through <= 9.1.7. | |
| Aplazada | Alta (7.1) | 0.25% | — | Basixonline Nex-formsAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Stored XSS.This issue affects NEX-Forms: from n/a through <= 9.1.7. | |
| Aplazada | Alta (7.1) | 0.19% | — | Zack Katz Icontact FOR Gravity FormsAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz iContact for Gravity Forms gravity-forms-icontact allows Reflected XSS.This issue affects iContact for Gravity Forms: from n/a through <= 1.3.2. | |
| Aplazada | Media (6.5) | 0.26% | — | PDF FOR WpformsAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for WPForms: from n/a through <= 6.3.0. | |
| Aplazada | Crítica (9.9) | 0.38% | — | Westerndeal Gsheetconnector-wpformsAI | 20/2/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in WesternDeal WPForms Google Sheet Connector gsheetconnector-wpforms allows Code Injection.This issue affects WPForms Google Sheet Connector: from n/a through <= 4.0.1. | |
| Aplazada | Media (4.3) | 0.25% | — | Official-mailerlite-sign-up-formsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in MailerLite MailerLite official-mailerlite-sign-up-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailerLite: from n/a through <= 1.7.18. | |
| Aplazada | Media (5.3) | 0.23% | — | Wpeverest Everest FormsAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in wpeverest Everest Forms everest-forms allows Code Injection.This issue affects Everest Forms: from n/a through <= 3.4.1. | |
| Aplazada | Media (4.3) | 0.31% | — | Kaliforms Kali FormsAI | 18/2/2026 | 17/6/2026 | The Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.8. This is due to the `get_items_permissions_check()` permission callback on the `/kaliforms/v1/forms/{id}` REST API endpoint only checking for the `edit_posts` capability without verifying… | |
| Aplazada | Media (4.3) | 0.27% | — | Rednao Smart FormsAI | 14/2/2026 | 17/6/2026 | The Smart Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'rednao_smart_forms_get_campaigns' AJAX action in all versions up to, and including, 2.6.99. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve… | |
| Aplazada | Alta (7.5) | 0.35% | — | Ninjaforms Ninja FormsAI | 10/2/2026 | 17/6/2026 | The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the resolution of `{post_meta:KEY}` merge tags… | |
| Aplazada | Media (6.4) | 0.29% | — | Fluentforms Fluent FormsAI | 10/2/2026 | 17/6/2026 | The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all versions up to, and including, 6.1.14 due to a combination of missing authorization checks, a leaked nonce, and insufficient input sanitization. The vulnerability allows Subscriber-level users to… | |
| Aplazada | Media (5.4) | 0.25% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 9/2/2026 | 17/6/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations… | |
| Aplazada | Media (4.3) | 0.21% | — | Approveme WP Forms Signature Contract ADD ONAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in approveme WP Forms Signature Contract Add-On wp-forms-signature-contract-add-on allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Forms Signature Contract Add-On: from n/a through <= 1.8.2. | |
| Aplazada | Media (5.3) | 0.32% | — | NexformsAI | 31/1/2026 | 17/6/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the NF5_Export_Forms class constructor in all versions up to, and including, 9.1.8. This makes it possible for unauthenticated attackers to export form configurations, that may include… | |
| Analizada | Media (6) | 0.46% | — | Umbraco Forms | 29/1/2026 | 17/6/2026 | Umbraco Forms is a form builder that integrates with the Umbraco content management system. It's possible for an authenticated backoffice-user to enumerate and traverse paths/files on the systems filesystem and read their contents, on Mac/Linux Umbraco installations using Forms. As Umbraco Cloud runs in a Windows… | |
| Aplazada | Crítica (9.8) | 13% | 💥 PoC | Snow Monkey FormsAI | 28/1/2026 | 17/6/2026 | The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dirpath' function in all versions up to, and including, 12.0.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can… | |
| Aplazada | Media (6.4) | 0.28% | — | Forms BridgeAI | 28/1/2026 | 17/6/2026 | The Forms Bridge – Infinite integrations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute in the 'financoop_campaign' shortcode in all versions up to, and including, 4.2.5. This is due to insufficient input sanitization and output escaping on the user-supplied 'id'… | |
| Aplazada | Media (5.3) | 0.45% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 28/1/2026 | 17/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the CSV export functionality in all versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to download sensitive form submission… | |
| Aplazada | Alta (8.6) | 0.60% | — | Harmonicdesign HdformsAI | 22/1/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Harmonic Design HDForms hdforms allows Path Traversal.This issue affects HDForms: from n/a through <= 1.6.1. | |
| Analizada | Alta (7.5) | 0.77% | — | Umbraco Forms | 16/1/2026 | 17/6/2026 | In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution. | |
| Aplazada | Media (6.4) | 0.21% | — | SpiceformsAI | 14/1/2026 | 17/6/2026 | The SpiceForms Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spiceforms' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.1) | 0.37% | — | Wpforms | 13/1/2026 | 17/6/2026 | WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can inject malicious scripts through the ListTable.php endpoint to execute arbitrary JavaScript in victim's browser. | |
| Aplazada | Media (6.8) | 0.29% | — | Nexforms NEX FormsAI | 9/1/2026 | 17/6/2026 | The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress plugin before 9.1.8 can be configured in such a way that could allow subscribers to perform Stored Cross-Site Scripting. |