Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.30% | — | Cimatti Contact Forms | 13/6/2023 | 17/6/2026 | The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms… | |
| Modificada | Media (5.4) | 0.51% | — | Codepeople Contact Form Email | 12/6/2023 | 17/6/2026 | The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability. | |
| Modificada | Media (5.3) | 0.63% | — | Wpmet Metform Elementor Contact Form Builder | 9/6/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update due to a missing capability check on the permalink_setup function in versions up to, and including, 3.3.0. This makes it possible for unauthenticated attackers to change the permalink structure. | |
| Modificada | Media (6.5) | 0.82% | — | Themefic Ultimate Addons FOR Contact Form 7 | 9/6/2023 | 17/6/2026 | The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and including, 3.1.23. This makes it possible for authenticated attackers of any authorization level to append additional SQL queries into already existing queries that can be used to… | |
| Modificada | Alta (7.8) | 0.71% | — | Wpmet Metform Elementor Contact Form Builder | 9/6/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to CSV injection in versions up to, and including, 3.3.0. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system… | |
| Modificada | Media (5.4) | 0.39% | — | Wpmet Metform Elementor Contact Form Builder | 9/6/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'fname' attribute of the 'mf_thankyou' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with contributor-level permissions or above, to… | |
| Modificada | Media (5.4) | 0.55% | — | Wpmet Metform Elementor Contact Form Builder | 9/6/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_last_name' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with contributor-level permissions or above, to inject arbitrary web… | |
| Modificada | Media (5.4) | 0.57% | — | Wpmet Metform Elementor Contact Form Builder | 9/6/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_first_name' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with contributor-level permissions or above, to inject arbitrary web… | |
| Modificada | Media (5.4) | 0.41% | — | Wpmet Metform Elementor Contact Form Builder | 9/6/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with contributor-level permissions or above, to inject arbitrary web scripts in… | |
| Modificada | Media (4.3) | 0.66% | — | Wpmet Metform Elementor Contact Form Builder | 9/6/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about any standard form field of any form… | |
| Modificada | Media (4.3) | 0.66% | — | Wpmet Metform Elementor Contact Form Builder | 9/6/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_transaction_id' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about the transaction ids of… | |
| Modificada | Media (4.3) | 0.60% | — | Wpmet Metform Elementor Contact Form Builder | 9/6/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_payment_status' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about the payment status of… | |
| Modificada | Media (4.3) | 0.60% | — | Wpmet Metform Elementor Contact Form Builder | 9/6/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_last_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about arbitrary form submissions,… | |
| Modificada | Media (6.5) | 0.73% | — | Wpmet Metform Elementor Contact Form Builder | 9/6/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_thankyou' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about form submissions, including… | |
| Modificada | Media (6.1) | 0.66% | — | Wpforms Contact Form | 7/6/2023 | 17/6/2026 | The Contact Form & SMTP Plugin by PirateForms plugin for WordPress is vulnerable to HTML injection in the ‘public/class-pirateforms-public.php’ file in versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Media (6.1) | 0.29% | — | Contact Form AND Calls TO Action BY Vcita | 3/6/2023 | 17/6/2026 | The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.10.5. This is due to missing nonce validation in the vcita-callback.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and… | |
| Modificada | Media (5.4) | 0.52% | — | Contact Form AND Calls TO Action BY Vcita | 3/6/2023 | 17/6/2026 | The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with the edit_posts… | |
| Modificada | Media (6.1) | 0.29% | — | Contact Form Builder BY Vcita | 3/6/2023 | 17/6/2026 | The Contact Form Builder by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.10.3. This is due to missing nonce validation on the ls_parse_vcita_callback function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject… | |
| Modificada | Media (5.4) | 0.51% | — | Contact Form Builder BY Vcita | 3/6/2023 | 17/6/2026 | The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 4.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with the edit_posts capability, such as… | |
| Modificada | Media (5.4) | 0.40% | — | Crmperks Contact Form Entries - Contact Form 7 Wpforms AND More | 28/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CRM Perks Contact Form Entries plugin <= 1.3.0 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Crmperks Integration FOR Contact Form 7 AND Zoho Crm, Bigin | 26/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin plugin <= 1.2.2 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions. | |
| Modificada | Alta (8.8) | 0.32% | — | Supsystic Contact Form | 17/5/2023 | 17/6/2026 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.24. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged request… | |
| Modificada | Media (6.1) | 0.38% | — | Webcodin WCP Contact Form | 15/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webcodin WCP Contact Form plugin <= 3.1.0 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Enhanced WP Contact Form Project Enhanced WP Contact Form | 10/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joost de Valk Enhanced WP Contact Form plugin <= 2.2.3 versions. |