Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

573 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.37%—Fullworksplugins Quick Contact Form25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions.
ModificadaMedia (6.1)0.54%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 717/4/202317/6/2026
The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a…
ModificadaMedia (5.4)0.48%—Fluentforms Contact Form10/4/202317/6/2026
The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in user with roles as low as contributor to inject arbitrary javascript into a form which will trigger for any visitor to the form or admins…
ModificadaMedia (6.1)0.55%—Bestwebsoft Contact Form9/4/202317/6/2026
A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic. Affected by this issue is the function bws_add_menu_render of the file bws_menu/bws_menu.php. The manipulation of the argument bwsmn_form_email leads to cross site scripting. The attack may be launched…
ModificadaAlta (8.8)0.36%—Bestwebsoft Contact Form9/4/202316/6/2026
A vulnerability was found in BestWebSoft Contact Form 3.21. It has been classified as problematic. This affects the function cntctfrm_settings_page of the file contact_form.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 3.22 is able to…
ModificadaMedia (6.1)0.38%—Cimatti Wordpress Contact Forms7/4/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.
ModificadaMedia (6.1)0.38%—Cimatti Wordpress Contact Forms7/4/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.
ModificadaMedia (5.4)0.39%—Fullworksplugins Quick Contact Form7/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions.
ModificadaMedia (6.1)0.51%—Bestwebsoft Contact Form5/4/202316/6/2026
A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPress. Affected by this issue is the function cntctfrm_display_form/cntctfrm_check_form of the file contact_form.php. The manipulation leads to cross site scripting. The attack may be launched remotely.…
ModificadaMedia (4.3)0.28%—Hasthemes Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks27/3/202317/6/2026
The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
ModificadaAlta (8.8)0.27%—Voidcoders Void Contact Form 7 Widget FOR Elementor Page Builder13/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions.
ModificadaMedia (6.1)29%💥 ExploitWpmet Metform Elementor Contact Form Builder2/3/202317/6/2026
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
ModificadaMedia (5.3)0.69%—Wpmet Metform Elementor Contact Form Builder2/3/202317/6/2026
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to reCaptcha Bypass in versions up to, and including, 3.2.1. This is due to insufficient server side checking on the captcha value submitted during a form submission. This makes it possible for unauthenticated attackers to bypass Captcha…
ModificadaCrítica (9.8)3.0%💥 PoCCodedropz Drag AND Drop Multiple File Upload - Contact Form 71/3/202317/6/2026
A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack…
ModificadaMedia (5.4)0.56%—Send PDF FOR Contact Form 7 Project Send PDF FOR Contact Form 76/2/202317/6/2026
The Send PDF for Contact Form 7 WordPress plugin before 0.9.9.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege…
ModificadaMedia (4.8)0.54%—Wpkube Simple Basic Contact Form26/12/202217/6/2026
The Simple Basic Contact Form WordPress plugin before 20221201 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaCrítica (9.8)3.9%—Ciphercoin Contact Form 7 Database Addon21/11/202217/6/2026
The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection
ModificadaCrítica (9.8)1.3%—Fluentforms Contact Form7/11/202217/6/2026
The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection
ModificadaMedia (4.3)0.59%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 717/10/202217/6/2026
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.
ModificadaAlta (7.5)0.61%—Redirection-for-contact-form7 Redirection FOR Contact Form 711/10/202217/6/2026
Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional extension (plugin) AccessiBe.
ModificadaMedia (4.8)0.67%—Zealousweb Generate PDF Using Contact Form 726/9/202217/6/2026
The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (5.4)0.55%—Contact Form BY Mega Forms Project Contact Form BY Mega Forms9/9/202217/6/2026
Authenticated (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Ali Khallad's Contact Form By Mega Forms plugin <= 1.2.4 at WordPress.
ModificadaMedia (6.1)0.62%—Webacetechs Contact Form DB - Elementor15/8/202217/6/2026
The Contact Form DB WordPress plugin before 1.8.0 does not sanitise and escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
ModificadaMedia (6.1)1.5%💥 ExploitContact Form 7 Captcha Project Contact Form 7 Captcha17/7/202217/6/2026
The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
ModificadaMedia (4.3)0.43%—Jquery Validation FOR Contact Form 7 Project Jquery Validation FOR Contact Form 717/7/202217/6/2026
The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change Blog options like default_role, users_can_register via a CSRF attack
Orbitaley — Vulnerabilidades