Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.37% | — | Fullworksplugins Quick Contact Form | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions. | |
| Modificada | Media (6.1) | 0.54% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 17/4/2023 | 17/6/2026 | The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a… | |
| Modificada | Media (5.4) | 0.48% | — | Fluentforms Contact Form | 10/4/2023 | 17/6/2026 | The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in user with roles as low as contributor to inject arbitrary javascript into a form which will trigger for any visitor to the form or admins… | |
| Modificada | Media (6.1) | 0.55% | — | Bestwebsoft Contact Form | 9/4/2023 | 17/6/2026 | A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic. Affected by this issue is the function bws_add_menu_render of the file bws_menu/bws_menu.php. The manipulation of the argument bwsmn_form_email leads to cross site scripting. The attack may be launched… | |
| Modificada | Alta (8.8) | 0.36% | — | Bestwebsoft Contact Form | 9/4/2023 | 16/6/2026 | A vulnerability was found in BestWebSoft Contact Form 3.21. It has been classified as problematic. This affects the function cntctfrm_settings_page of the file contact_form.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 3.22 is able to… | |
| Modificada | Media (6.1) | 0.38% | — | Cimatti Wordpress Contact Forms | 7/4/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Cimatti Wordpress Contact Forms | 7/4/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions. | |
| Modificada | Media (5.4) | 0.39% | — | Fullworksplugins Quick Contact Form | 7/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions. | |
| Modificada | Media (6.1) | 0.51% | — | Bestwebsoft Contact Form | 5/4/2023 | 16/6/2026 | A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPress. Affected by this issue is the function cntctfrm_display_form/cntctfrm_check_form of the file contact_form.php. The manipulation leads to cross site scripting. The attack may be launched remotely.… | |
| Modificada | Media (4.3) | 0.28% | — | Hasthemes Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks | 27/3/2023 | 17/6/2026 | The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | |
| Modificada | Alta (8.8) | 0.27% | — | Voidcoders Void Contact Form 7 Widget FOR Elementor Page Builder | 13/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions. | |
| Modificada | Media (6.1) | 29% | 💥 Exploit | Wpmet Metform Elementor Contact Form Builder | 2/3/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Modificada | Media (5.3) | 0.69% | — | Wpmet Metform Elementor Contact Form Builder | 2/3/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to reCaptcha Bypass in versions up to, and including, 3.2.1. This is due to insufficient server side checking on the captcha value submitted during a form submission. This makes it possible for unauthenticated attackers to bypass Captcha… | |
| Modificada | Crítica (9.8) | 3.0% | 💥 PoC | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 1/3/2023 | 17/6/2026 | A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack… | |
| Modificada | Media (5.4) | 0.56% | — | Send PDF FOR Contact Form 7 Project Send PDF FOR Contact Form 7 | 6/2/2023 | 17/6/2026 | The Send PDF for Contact Form 7 WordPress plugin before 0.9.9.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege… | |
| Modificada | Media (4.8) | 0.54% | — | Wpkube Simple Basic Contact Form | 26/12/2022 | 17/6/2026 | The Simple Basic Contact Form WordPress plugin before 20221201 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Crítica (9.8) | 3.9% | — | Ciphercoin Contact Form 7 Database Addon | 21/11/2022 | 17/6/2026 | The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection | |
| Modificada | Crítica (9.8) | 1.3% | — | Fluentforms Contact Form | 7/11/2022 | 17/6/2026 | The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection | |
| Modificada | Media (4.3) | 0.59% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 17/10/2022 | 17/6/2026 | The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form. | |
| Modificada | Alta (7.5) | 0.61% | — | Redirection-for-contact-form7 Redirection FOR Contact Form 7 | 11/10/2022 | 17/6/2026 | Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional extension (plugin) AccessiBe. | |
| Modificada | Media (4.8) | 0.67% | — | Zealousweb Generate PDF Using Contact Form 7 | 26/9/2022 | 17/6/2026 | The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.4) | 0.55% | — | Contact Form BY Mega Forms Project Contact Form BY Mega Forms | 9/9/2022 | 17/6/2026 | Authenticated (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Ali Khallad's Contact Form By Mega Forms plugin <= 1.2.4 at WordPress. | |
| Modificada | Media (6.1) | 0.62% | — | Webacetechs Contact Form DB - Elementor | 15/8/2022 | 17/6/2026 | The Contact Form DB WordPress plugin before 1.8.0 does not sanitise and escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 1.5% | 💥 Exploit | Contact Form 7 Captcha Project Contact Form 7 Captcha | 17/7/2022 | 17/6/2026 | The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers | |
| Modificada | Media (4.3) | 0.43% | — | Jquery Validation FOR Contact Form 7 Project Jquery Validation FOR Contact Form 7 | 17/7/2022 | 17/6/2026 | The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change Blog options like default_role, users_can_register via a CSRF attack |