Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
125 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.25% | — | Whitestudio Easy Form BuilderAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <= 3.8.20. | |
| Aplazada | Media (4.3) | 0.15% | — | Surveyjs Drag Drop Form BuilderAI | 2/12/2025 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12.20. This is due to missing nonce validation on the SurveyJS_DeleteSurvey AJAX action. This makes it possible for unauthenticated attackers to delete surveys via a… | |
| Aplazada | Crítica (9.3) | 0.30% | — | Whitestudio Easy Form BuilderAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder: from n/a through <= 3.8.15. | |
| Aplazada | Alta (8.1) | 1.0% | — | Emarketdesign EMD Form Builder LiteAI | 6/8/2025 | 17/6/2026 | Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible… | |
| Aplazada | Alta (7.1) | 0.26% | — | Wpquark Eform - Wordpress Form BuilderAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPQuark eForm - WordPress Form Builder wp-fsqm-pro allows Reflected XSS.This issue affects eForm - WordPress Form Builder: from n/a through < 4.19.1. | |
| Aplazada | Crítica (9.3) | 0.43% | — | Kamleshyadav Pixel Wordpress Form Builder Plugin & AutoresponderAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder pixel-formbuilder allows Blind SQL Injection.This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through <= 1.0.2. | |
| Aplazada | Media (5.4) | 0.15% | — | Kamleshyadav Pixel Wordpress Form Builder Plugin AND AutoresponderAI | 16/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder pixel-formbuilder allows Cross Site Request Forgery.This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through <= 1.0.3. | |
| Analizada | Baja (2.7) | 0.40% | — | Spiderteams Applyonline - Application Form Builder AND Manager | 15/5/2025 | 17/6/2026 | The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain | |
| Modificada | Media (4.8) | 0.23% | — | Vikasratudi Lifetime Free Drag & Drop Contact Form Builder | 22/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VPSUForm v-form allows Stored XSS.This issue affects VPSUForm: from n/a through <= 3.1.14. | |
| Aplazada | Media (6.5) | 0.27% | — | Vcita Contact Form BuilderAI | 10/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyale-vc Contact Form Builder by vcita contact-form-with-a-meeting-scheduler-by-vcita allows DOM-Based XSS.This issue affects Contact Form Builder by vcita: from n/a through <= 4.10.2. | |
| Aplazada | Alta (8.8) | 0.77% | — | Surveyjs Drag AND Drop Wordpress Form BuilderAI | 1/3/2025 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to arbitrary file deletion due to a missing capability check on the callback function of the SurveyJS_DeleteFile class in all versions up to, and including, 1.12.17. This… | |
| Analizada | Media (6.5) | 0.40% | — | Bitapps Contact Form Builder | 25/1/2025 | 17/6/2026 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.17.4 via the Webhooks integration. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (8.5) | 0.46% | — | Codepeople Form Builder CPAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople Form Builder CP cp-easy-form-builder allows SQL Injection.This issue affects Form Builder CP: from n/a through <= 1.2.41. | |
| Analizada | Media (6.5) | 0.45% | — | Codepeople Form Builder CP | 24/1/2025 | 17/6/2026 | The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'CP_EASY_FORM_WILL_APPEAR_HERE' shortcode in all versions up to, and including, 1.2.41 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (6.4) | 0.25% | — | Whitestudio Easy Form BuilderAI | 8/1/2025 | 17/6/2026 | The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'add_form_Emsfb' AJAX action in all versions up to, and including, 3.8.8 due to insufficient input… | |
| Aplazada | Media (4.3) | 0.34% | — | Farhan Noor Applyonline Application Form Builder AND ManagerAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Farhan Noor ApplyOnline – Application Form Builder and Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ApplyOnline – Application Form Builder and Manager: from n/a through 2.5.3. | |
| Aplazada | Media (6.4) | 0.29% | — | Mightyforms Contact Form Survey AND Form BuilderAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in mightyforms Contact Form, Survey & Form Builder – MightyForms mightyforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form, Survey & Form Builder – MightyForms: from n/a through <= 1.3.9. | |
| Modificada | Media (6.1) | 0.33% | — | Reputeinfosystems Arforms Form Builder | 9/12/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in reputeinfosystems ARForms Form Builder arforms-form-builder allows Code Injection.This issue affects ARForms Form Builder: from n/a through <= 1.7.1. | |
| Modificada | Crítica (9.8) | 0.62% | — | Wpmet Metform Elementor Contact Form Builder | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Roxnor Metform metform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Metform: from n/a through <= 3.4.0. | |
| Aplazada | Media (6.4) | 0.33% | — | Vcita Contact Form BuilderAI | 5/12/2024 | 17/6/2026 | The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's livesite-pay shortcode in all versions up to, and including, 4.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.3) | 1.1% | — | Strategy11 Formidable Form Builder | 16/10/2024 | 17/6/2026 | The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form. | |
| Analizada | Media (6.1) | 1.1% | — | Strategy11 Formidable Form Builder | 16/10/2024 | 17/6/2026 | The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Analizada | Media (6.5) | 0.92% | — | Bitapps Contact Form Builder | 20/8/2024 | 17/6/2026 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the iconRemove function in versions 2.0 to 2.13.4. This makes it possible for… | |
| Analizada | Alta (7.2) | 0.51% | — | Bitapps Contact Form Builder | 20/8/2024 | 17/6/2026 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the id parameter in versions 2.0 to 2.13.9 due to insufficient escaping on the user-supplied parameter and lack of sufficient… | |
| Analizada | Crítica (9) | 1.0% | — | Bitapps Contact Form Builder | 20/8/2024 | 17/6/2026 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in multiple functions in versions 2.0 to 2.13.9. This makes it possible for… |