Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Wpzoom Forms Contact Form Plugin FOR GutenbergAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Contact Form 7 Paypal AND Stripe Add-onAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions. | |
| Aplazada | Crítica (9.2) | 0.42% | — | Camaleon CMS Cama Contact FormAITuzitio Camaleon CMSAI | 12/8/2026 | 26/8/2026 | CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which lacks proper authorization controls.… | |
| Aplazada | Alta (7.2) | 0.38% | — | Camaleon AttackAICamaleon Front CacheAICamaleon Cama Meta TAGAICamaleon Cama Contact FormAI+1 | 12/8/2026 | 26/8/2026 | CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime… | |
| Aplazada | Alta (7.5) | 0.43% | — | Itpathsolutions Contact Form TO ANY APIAI | 10/8/2026 | 26/8/2026 | The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users. | |
| Aplazada | Alta (7.5) | 0.43% | — | HT Contact FormAI | 10/8/2026 | 26/8/2026 | The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts. | |
| Aplazada | Media (6.4) | 0.26% | — | Ultraaddons Ultra Addons FOR Contact Form 7AI | 7/8/2026 | 12/8/2026 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slider 'data-label' and 'data-separator' attributes in all versions up to, and including, 3.5.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (4.4) | 0.31% | — | Contact Form 7 Dynamic Text ExtensionAI | 5/8/2026 | 12/8/2026 | The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0.5. This is due to insufficient output escaping on form shortcode keys displayed in the admin "Scan Forms for Post Meta and User Data Keys" page. This makes it possible… | |
| Aplazada | Media (6.8) | 0.39% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 4/8/2026 | 26/8/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated… | |
| Aplazada | Media (6.4) | 0.33% | — | Itpathsolutions Contact Form TO ANY APIAI | 29/7/2026 | 30/7/2026 | The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Alta (7.1) | 0.25% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 28/7/2026 | 28/7/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.1) | 0.25% | — | Themefic Ultimate Addons FOR Contact Form 7AI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Contact Form 7AI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions. | |
| Aplazada | Media (4.7) | 0.29% | — | Contact Form 7AI | 27/7/2026 | 27/7/2026 | The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow. | |
| Aplazada | Media (6.5) | 0.47% | — | Contact Form 7 Dynamic Text ExtensionAI | 22/7/2026 | 29/9/2026 | The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible… | |
| Aplazada | Media (5.3) | 0.39% | — | Kali Forms Contact Form AND Drag AND Drop BuilderAI | 15/7/2026 | 15/7/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows unauthenticated users to upload files to the WordPress… | |
| Aplazada | Alta (7.1) | 0.25% | — | Crmperks Contact Form EntriesAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Contact Form Entries contact-form-entries allows Reflected XSS.This issue affects Contact Form Entries: from n/a through <= 1.5.2. | |
| Aplazada | Alta (7.1) | 0.25% | — | Kofimokome Message Filter FOR Contact Form 7AI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter allows Reflected XSS.This issue affects Message Filter for Contact Form 7: from n/a through <= 1.6.3.8. | |
| Aplazada | Media (5) | 0.22% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 13/7/2026 | 13/7/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field value, allowing unauthenticated users to inject arbitrary PHP objects that are instantiated when an administrator views the stored entry.… | |
| Aplazada | Alta (7.2) | 0.59% | — | Connect Contact Form 7 AND MailchimpAI | 9/7/2026 | 9/7/2026 | The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp Merge Field Values in all versions up to, and including, 0.9.78.06 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.5) | 0.34% | — | Advanced Contact Form 7 DBAI | 2/7/2026 | 2/7/2026 | Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions. | |
| Aplazada | Media (6.5) | 0.43% | — | Crmperks Contact Form EntriesAI | 2/7/2026 | 2/7/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, and including, 1.5.1. The function reads raw_value from Elementor Pro's Form_Record object for upload-type fields and passes it directly to PHP's… | |
| Aplazada | Media (5.3) | 0.40% | — | Advanced Contact Form 7 Compact DBAI | 24/6/2026 | 25/6/2026 | The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the cf7cdb_ajax_delete_user() function in versions up to, and including, 1.0.0. The handler is registered against both `wp_ajax_cf7cdb_delete` and… | |
| Aplazada | Alta (7.1) | 0.27% | — | Wpkube Simple Basic Contact FormAI | 23/6/2026 | 23/6/2026 | The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form output on validation errors, leading to a Reflected Cross-Site Scripting vulnerability that unauthenticated attackers can exploit against site visitors via a crafted link or… | |
| Aplazada | Alta (8.1) | 1.0% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 20/6/2026 | 22/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the… |