Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.8) | 0.27% | — | Wikimedia Mediawiki PageformsAI | 20/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki PageForms extension allows Stored XSS.This issue affects MediaWiki PageForms extension: 1.44. | |
| Aplazada | Alta (8.3) | 0.55% | — | Sveltekit-superformsAI | 15/10/2025 | 17/6/2026 | sveltekit-superforms makes SvelteKit forms a pleasure to use. sveltekit-superforms v2.27.3 and prior are susceptible to a prototype pollution vulnerability within the parseFormData function of formData.js. An attacker can inject string and array properties into Object.prototype, leading to denial of service, type… | |
| Aplazada | Media (4.3) | 0.25% | — | Brainstormforce SureformsAI | 14/10/2025 | 17/6/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. This makes it… | |
| Aplazada | Baja (2.4) | 0.15% | — | Gsheetconnector FOR Gravity FormsAI | 11/10/2025 | 17/6/2026 | The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 1.3.23. This is due to missing or incorrect nonce validation on the activate_plugin and deactivate_plugin functions. This makes it possible for attackers to trick authenticated… | |
| Aplazada | Alta (8.8) | 0.43% | — | Gsheetconnector FOR Gravity FormsAI | 11/10/2025 | 30/9/2026 | The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, or equal to, 1.3.27. This is due to a missing capability check on the 'install_plugin' function. This makes it possible for authenticated attackers, with subscriber-level access and above to install… | |
| Aplazada | Media (4.9) | 0.32% | — | Basix IO NEX FormsAI | 11/10/2025 | 30/9/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the action nf_load_form_entries in all versions up to, and including, 9.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Media (4.3) | 0.15% | — | Paypal FormsAI | 3/10/2025 | 30/9/2026 | The PayPal Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing nonce validation on the form creation and management functions. This makes it possible for unauthenticated attackers to create new PayPal forms and modify PayPal payment… | |
| Aplazada | Media (4.3) | 0.13% | — | CformsAI | 27/9/2025 | 17/6/2026 | The cForms – Light speed fast Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the cforms_api function. This makes it possible for unauthenticated attackers to modify forms and their… | |
| Analizada | Media (4.3) | 0.16% | — | Ninjaforms Ninja Forms | 27/9/2025 | 17/6/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticated attackers to opt… | |
| Analizada | Media (5.4) | 0.16% | — | Ninjaforms Ninja Forms | 27/9/2025 | 17/6/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete those… | |
| Aplazada | Media (4.3) | 0.19% | — | Wpshuffle WP Subscription Forms PROAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in wpshuffle WP Subscription Forms PRO wp-subscription-forms-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Subscription Forms PRO: from n/a through <= 2.0.5. | |
| Aplazada | Baja (3.5) | 0.19% | — | Brainstormforce SureformsAI | 23/9/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.9.1 does not sanitise and escape some parameters when outputing them in the page, which could allow admin and above users to perform Cross-Site Scripting attacks. | |
| Aplazada | Media (6.5) | 0.20% | — | Fatcatapps Getresponse FormsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps GetResponse Forms getresponse allows Stored XSS.This issue affects GetResponse Forms: from n/a through <= 2.6.0. | |
| Aplazada | Media (4.7) | 0.28% | — | Crmperks WP Gravity Forms Keap InfusionsoftAI | 22/9/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows Phishing.This issue affects WP Gravity Forms Keap/Infusionsoft: from n/a through <= 1.2.6. | |
| Aplazada | Media (4.3) | 0.16% | — | Piotnet FormsAI | 22/9/2025 | 30/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in piotnetdotcom Piotnet Forms piotnetforms allows Cross Site Request Forgery.This issue affects Piotnet Forms: from n/a through <= 1.0.30. | |
| Aplazada | Media (4.3) | 0.19% | — | Brainstormforce SureformsAI | 20/9/2025 | 17/6/2026 | The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.86% | — | Embed PDF FOR WpformsAI | 19/9/2025 | 17/6/2026 | The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_handler_download_pdf_media function in all versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload… | |
| Analizada | Crítica (9.8) | 0.54% | — | Ninjaforms Ninja Forms | 18/9/2025 | 17/6/2026 | The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog. | |
| Aplazada | Alta (8.5) | 0.20% | — | Digilent WaveformsAI | 15/9/2025 | 17/6/2026 | Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .DWF3WORK file. This vulnerability affects Digilent WaveForms 3.24.3 and prior versions. | |
| Aplazada | Media (6.5) | 0.21% | — | Givecloud Donation Forms WPAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in givecloud Donation Forms WP by Givecloud donation-forms-by-givecloud allows Stored XSS.This issue affects Donation Forms WP by Givecloud: from n/a through <= 1.0.9. | |
| Aplazada | Alta (7.1) | 0.52% | — | Liferay DXPAILiferay Kaleo Forms AdminAILiferay PortalAI | 4/9/2025 | 17/6/2026 | Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via… | |
| Aplazada | Media (5.4) | 0.22% | — | Contact Form BY Mega FormsAI | 3/9/2025 | 30/9/2026 | Missing Authorization vulnerability in Ali Khallad Contact Form By Mega Forms mega-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form By Mega Forms: from n/a through <= 1.6.1. | |
| Aplazada | Media (6.5) | 0.21% | — | PDF FOR WpformsAI | 3/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Stored XSS.This issue affects PDF for WPForms: from n/a through <= 6.2.1. | |
| Aplazada | Media (6.5) | 0.58% | — | Fluentforms Fluent FormsAI | 3/9/2025 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 to 6.1.1 via deserialization of untrusted input in the parseUserProperties function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.30% | — | Iats Online FormsAI | 29/8/2025 | 17/6/2026 | The iATS Online Forms plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order' parameter in all versions up to, and including, 1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… |