Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.74% | — | Fluentforms Contact Form | 31/10/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contact Form - WPManageNinja LLC Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms fluentform allows SQL Injection.This issue affects Contact Form Plugin – Fastest Contact Form… | |
| Modificada | Media (6.1) | 0.33% | — | Wpdevart Contact Form Builder | 26/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Contact Form Builder, Contact Widget plugin <= 2.1.6 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Mailmunch Constant Contact Forms | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MailMunch Constant Contact Forms by MailMunch plugin <= 2.0.10 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Supsystic Contact Form | 12/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Contact Form by Supsystic plugin <= 1.7.27 versions. | |
| Modificada | Media (5.4) | 0.34% | — | Leechesnutt Slick Contact Forms | 10/10/2023 | 17/6/2026 | The Slick Contact Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcscf-link' shortcode in versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Modificada | Alta (8.8) | 0.27% | — | Nickduncan Contact Form | 9/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in NickDuncan Contact Form plugin <= 2.0.10 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Gopiplus Popup Contact Form | 2/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Popup contact form plugin <= 7.1 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Gopiplus Popup Contact Form | 2/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Popup contact form plugin <= 7.1 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Leaptodigital Contact Form Website TO Workflow Tool | 2/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Leap Contractor Contact Form Website to Workflow Tool plugin <= 4.0.0 versions. | |
| Modificada | Media (6.1) | 0.39% | — | Themefic Ultimate Addons FOR Contact Form 7 | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.2.0 versions. | |
| Modificada | Media (5.4) | 0.41% | — | Contact Form BY Formget | 23/9/2023 | 17/6/2026 | The Contact Form by FormGet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formget' shortcode in versions up to, and including, 5.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Modificada | Media (4.3) | 0.58% | — | Wpmet Metform Elementor Contact Form Builder | 31/8/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about arbitrary form submissions,… | |
| Modificada | Media (4.8) | 0.44% | — | Ninjaforms Ninja Forms Contact Form | 30/8/2023 | 17/6/2026 | The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by a HTML Injection security vulnerability. | |
| Modificada | Media (4.8) | 0.44% | — | Bitapps Contact Form Builder | 14/8/2023 | 17/6/2026 | The Contact Form Builder by Bit Form WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.49% | — | Themefic Ultimate Addons FOR Contact Form 7 | 14/8/2023 | 17/6/2026 | The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Media (4.8) | 0.47% | — | Themefic Ultimate Addons FOR Contact Form 7 | 14/8/2023 | 17/6/2026 | The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | Creative-solutions Contact Form Generator | 10/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <= 2.5.5 versions. | |
| Modificada | Media (4.3) | 0.40% | — | Wpmet Metform Elementor Contact Form Builder | 12/7/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on the permalink_setup function. This makes it possible for unauthenticated attackers to change the permalink… | |
| Modificada | Alta (8.8) | 0.31% | — | Wpplugin Contact Form 7 Redirect & Thank YOU Page | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 Redirect & Thank You Page plugin <= 1.0.3 versions. | |
| Modificada | Media (4.3) | 0.46% | — | Cf7style Contact Form 7 Style | 1/7/2023 | 17/6/2026 | The Contact Form 7 Style plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2. This is due to missing or incorrect nonce validation on the manage_wp_posts_be_qe_save_post() function. This makes it possible for unauthenticated attackers to quick edit templates via a… | |
| Modificada | Media (4.8) | 0.37% | — | Simplemodal Contact Form Project Simplemodal Contact Form | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Martin SimpleModal Contact Form (SMCF) plugin <= 1.2.9 versions. | |
| Modificada | Media (6.1) | 0.40% | — | Wpforms Contact FormWpforms | 22/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions. | |
| Modificada | Crítica (9.8) | 0.65% | — | Themefic Ultimate Addons FOR Contact Form 7 | 19/6/2023 | 17/6/2026 | Unauth. SQL Injection (SQLi) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.1.23 versions. | |
| Modificada | Media (4.8) | 0.44% | — | Crmperks Integration FOR Contact Form 7 AND Zoho Crm, Bigin | 19/6/2023 | 17/6/2026 | The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin | |
| Modificada | Media (6.1) | 0.38% | — | Zestard Admin Side Data Storage FOR Contact Form 7 | 15/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact Form 7 plugin <= 1.1.1 versions. |