Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.7) | 0.32% | — | Crmperks WP Gravity Forms ZendeskAI | 7/5/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zendesk gf-zendesk allows Phishing.This issue affects WP Gravity Forms Zendesk: from n/a through <= 1.1.2. | |
| Aplazada | Media (4.7) | 0.32% | — | Crmperks WP Gravity Forms Dynamics CRMAI | 7/5/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Dynamics CRM gf-dynamics-crm allows Phishing.This issue affects WP Gravity Forms Dynamics CRM: from n/a through <= 1.1.4. | |
| Analizada | Baja (3.5) | 0.27% | — | Brainstormforce Sureforms | 2/5/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Baja (3.5) | 0.31% | — | Brainstormforce Sureforms | 2/5/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (5.5) | 0.25% | — | Rocketgenius Gravity Forms Webhooks | 1/5/2025 | 17/6/2026 | The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.0 via the 'process_feed' method of the GF_Webhooks class This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to… | |
| Analizada | Media (4.9) | 0.35% | — | Brainstormforce Sureforms | 30/4/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action | |
| Aplazada | Alta (7.3) | 0.54% | — | Create Custom Forms FOR Wordpress With A Smart Form Plugin FOR Smart BusinessesAI | 26/4/2025 | 17/6/2026 | The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.4. This is due to the software allowing users to execute an action that does not properly validate a value before running… | |
| Aplazada | Media (6.5) | 0.27% | — | Creatorteam Zoho Creator FormsAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreatorTeam Zoho Creator Forms allows Stored XSS. This issue affects Zoho Creator Forms: from n/a through 1.0.5. | |
| Modificada | Media (5.4) | 0.22% | — | Linksoftwarellc Html Forms | 22/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms html-forms allows Stored XSS.This issue affects HTML Forms: from n/a through <= 1.5.2. | |
| Aplazada | Media (5.9) | 0.27% | — | Maros Pristas Gravity Forms CSS Themes With Fontawesome AND Placeholder SupportAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maros Pristas Gravity Forms CSS Themes with Fontawesome and Placeholders gravity-forms-css-themes-with-fontawesome-and-placeholder-support allows Stored XSS.This issue affects Gravity Forms CSS Themes with Fontawesome… | |
| Aplazada | Alta (7.1) | 0.38% | — | Fromdoppler Doppler FormsAI | 17/4/2025 | 17/6/2026 | Missing Authorization vulnerability in fromdoppler Doppler Forms doppler-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Doppler Forms: from n/a through <= 2.4.6. | |
| Analizada | Media (5.4) | 0.29% | — | Wpmudev Forminator Forms | 17/4/2025 | 17/6/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘limit’ parameter in all versions up to, and including, 1.42.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Media (5.3) | 0.21% | — | Wpmudev Forminator Forms | 17/4/2025 | 17/6/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 1.42.0 via the 'handle_stripe_single' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (6.4) | 0.32% | — | Fluentforms Fluent FormsAI | 17/4/2025 | 17/6/2026 | The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (5.4) | 0.39% | — | Wpshuffle WP Subscription FormsAI | 16/4/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Shuffle WP Subscription Forms wp-subscription-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Subscription Forms: from n/a through <= 1.2.3. | |
| Aplazada | Media (5.4) | 0.44% | — | W3eden Live FormsAI | 16/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Shahjada Live Forms liveforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live Forms: from n/a through <= 4.8.4. | |
| Analizada | Crítica (9.8) | 1.2% | — | Wpeverest Everest Forms | 11/4/2025 | 17/6/2026 | The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.1 via deserialization of untrusted input from the 'field_value' parameter. This makes it possible for unauthenticated… | |
| Analizada | Media (6.3) | 0.32% | — | Wpeverest Everest Forms | 11/4/2025 | 17/6/2026 | The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.1.1. This is due to the software allowing users to execute an action that does not properly validate a value… | |
| Modificada | Media (6.1) | 0.35% | — | Wpeverest Everest Forms | 11/4/2025 | 17/6/2026 | The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form_id' parameter in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.5) | 0.32% | — | Flothemes FLO FormsAI | 10/4/2025 | 17/6/2026 | Missing Authorization vulnerability in flothemesplugins Flo Forms flo-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flo Forms: from n/a through <= 1.0.43. | |
| Aplazada | Baja (2.7) | 0.39% | — | Piotnet FormsAI | 10/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in piotnetdotcom Piotnet Forms piotnetforms.This issue affects Piotnet Forms: from n/a through <= 1.0.30. | |
| Aplazada | Media (6.4) | 0.33% | — | Payment Forms FOR PaystackAI | 10/4/2025 | 17/6/2026 | The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'datepicker', 'textarea', and 'text' in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Alta (7.5) | 0.89% | — | Wpshuffle WP Subscription FormsAI | 9/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle WP Subscription Forms wp-subscription-forms allows PHP Local File Inclusion.This issue affects WP Subscription Forms: from n/a through <= 1.2.4. | |
| Aplazada | Alta (7.1) | 0.17% | — | Fromdoppler Doppler FormsAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in fromdoppler Doppler Forms doppler-form allows Stored XSS.This issue affects Doppler Forms: from n/a through <= 2.5.1. | |
| Aplazada | Media (4.3) | 0.25% | — | W3eden Live FormsAI | 8/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Shahjada Live Forms liveforms.This issue affects Live Forms: from n/a through <= 4.8.5. |