Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.38% | — | Add-ons.org Drag AND Drop File Upload FOR Elementor FormsAI | 28/8/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms drag-and-drop-file-upload-for-elementor-forms allows Upload a Web Shell to a Web Server.This issue affects Drag and Drop File Upload for Elementor Forms: from n/a through <= 1.5.3. | |
| Aplazada | Media (6.5) | 0.17% | — | Add-ons.org PDF FOR Elementor FormsAI | 27/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Stored XSS.This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through <= 6.2.0. | |
| Aplazada | Alta (8.8) | 0.17% | — | Basixonline Nex-formsAI | 20/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Cross Site Request Forgery.This issue affects NEX-Forms: from n/a through <= 9.1.3. | |
| Aplazada | Media (5.4) | 0.14% | — | Crmperks Connector FOR Gravity Forms AND Google SheetsAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Cross Site Request Forgery.This issue affects Connector for Gravity Forms and Google Sheets: from n/a through <= 1.2.4. | |
| Aplazada | Media (4.7) | 0.26% | — | Crmperks Connector FOR Gravity Forms AND Google SheetsAI | 14/8/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Phishing.This issue affects Connector for Gravity Forms and Google Sheets: from n/a through <= 1.2.4. | |
| Aplazada | Crítica (9.9) | 0.43% | — | Madeit FormsAI | 14/8/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms forms-by-made-it allows Upload a Web Shell to a Web Server.This issue affects Forms: from n/a through <= 2.9.0. | |
| Aplazada | Crítica (9.8) | 1.3% | 💥 PoC | Database FOR Contact Form 7AIWpformsAIElementor FormsAI | 13/8/2025 | 17/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization of untrusted input in the get_lead_detail function. This makes it possible for unauthenticated attackers to inject a PHP Object. The… | |
| Analizada | Alta (8.6) | 77% | — | Adobe Experience Manager Forms | 5/8/2025 | 17/6/2026 | Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed.… | |
| Analizada | Crítica (10) | 88% | ⚠ Explotación activa💥 PoC | Adobe Experience Manager Forms | 5/8/2025 | 17/6/2026 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is… | |
| Analizada | Media (5.8) | 0.18% | — | Brainstormforce Sureforms | 1/8/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users. | |
| Aplazada | Alta (7.2) | 0.53% | — | Ninjaforms NinjascannerAI | 31/7/2025 | 17/6/2026 | The NinjaScanner – Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'nscan_ajax_quarantine' and 'nscan_quarantine_select' functions in all versions up to, and including, 3.2.5. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Integration FOR Google Sheets AND Contact Form 7 Wpforms Elementor Ninja FormsAI | 19/7/2025 | 17/6/2026 | The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.1 via deserialization of untrusted input within the verify_field_val() function. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.6) | 0.26% | — | Balbooa FormsAIJoomlaAI | 18/7/2025 | 17/6/2026 | A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter. | |
| Aplazada | Crítica (9.8) | 0.91% | — | GB Forms DBAI | 11/7/2025 | 17/6/2026 | The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2 via the gbfdb_talk_to_front() function. This is due to the function accepting user input and then passing that through call_user_func(). This makes it possible for unauthenticated attackers to… | |
| Analizada | Alta (7.5) | 0.55% | — | Brainstormforce Sureforms | 9/7/2025 | 17/6/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.3 via the use of file_exists() in the delete_entry_files() function without restriction on the path provided. This makes it possible for unauthenticated… | |
| Analizada | Alta (8.1) | 1.0% | — | Brainstormforce Sureforms | 9/7/2025 | 17/6/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to delete arbitrary… | |
| Analizada | Alta (7.5) | 0.41% | 💥 PoC | Optinlyhq Gozen Forms | 4/7/2025 | 17/6/2026 | The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the emdedSc() function in all versions up to, and including, 1.1.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Alta (7.5) | 0.40% | 💥 PoC | Optinlyhq Gozen Forms | 4/7/2025 | 17/6/2026 | The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the dirGZActiveForm() function in all versions up to, and including, 1.1.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Aplazada | Media (6.5) | 0.23% | — | Aman Popup Popup Addon FOR Ninja FormsAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman Popup addon for Ninja Forms popup-addon-for-ninja-forms allows DOM-Based XSS.This issue affects Popup addon for Ninja Forms: from n/a through <= 3.4. | |
| Aplazada | Media (5.4) | 0.15% | — | Pluginscafe Address Autocomplete VIA Google FOR Gravity FormsAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PluginsCafe Address Autocomplete via Google for Gravity Forms gf-google-address-autocomplete allows Cross Site Request Forgery.This issue affects Address Autocomplete via Google for Gravity Forms: from n/a through <= 1.3.4. | |
| Analizada | Media (5.4) | 0.24% | — | Ninjaforms Ninja Forms | 27/6/2025 | 17/6/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to insufficient output escaping on user data passed through the template. This makes it possible for… | |
| Analizada | Alta (7.5) | 0.68% | — | Wpeverest Everest Forms | 25/6/2025 | 17/6/2026 | The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily… | |
| Aplazada | Media (4.3) | 0.22% | — | Imran Tauqeer Cubewp FormsAI | 17/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP Forms: from n/a through <= 1.1.5. | |
| Aplazada | Media (5) | 0.28% | — | PDF FOR WpformsAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for WPForms: from n/a through <= 5.5.0. | |
| Aplazada | Media (4.3) | 0.16% | — | Matthias Nordwig Gdpr-compliant-recaptcha-for-all-formsAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Matthias Nordwig Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant gdpr-compliant-recaptcha-for-all-forms allows Cross Site Request Forgery.This issue affects Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant: from n/a through… |