Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
1178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.18% | — | WpformsAI | 24/9/2026 | 24/9/2026 | The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate subscription cancellation against payments created by other applications on the… | |
| Aplazada | Alta (7.1) | 0.18% | — | Ninjaforms Ninja FormsAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | |
| Aplazada | Alta (8.5) | 0.22% | — | Mollie FormsAI | 23/9/2026 | 23/9/2026 | Contributor SQL Injection in Mollie Forms <= 2.11.0 versions. | |
| Aplazada | Media (6.8) | 0.24% | — | Subscribe FormsAI | 23/9/2026 | 23/9/2026 | The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who views a page embedding the… | |
| Aplazada | Baja (3.7) | 0.15% | — | Wpmudev Forminator FormsAI | 23/9/2026 | 23/9/2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail… | |
| Pendiente de análisis | Crítica (9.6) | 0.73% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 23/9/2026 | Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope… | |
| Pendiente de análisis | Alta (8.7) | 0.81% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 23/9/2026 | Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction.… | |
| Pendiente de análisis | Crítica (9.1) | 1.2% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 23/9/2026 | Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user… | |
| Pendiente de análisis | Crítica (10) | 1.2% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 25/9/2026 | Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is… | |
| Pendiente de análisis | Alta (8.1) | 1.2% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 22/9/2026 | Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the… | |
| Pendiente de análisis | Alta (7.1) | 1.5% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 24/9/2026 | Adobe Experience Manager Forms JEE is affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of… | |
| Aplazada | Alta (7.2) | 0.41% | — | Ninjaforms Ninja FormsAI | 22/9/2026 | 22/9/2026 | Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin. | |
| Aplazada | Alta (8.8) | 0.35% | — | Ninjaforms Ninja FormsAI | 22/9/2026 | 22/9/2026 | The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the… | |
| Aplazada | Alta (7.5) | 0.30% | — | Ninjaforms Ninja FormsAI | 22/9/2026 | 22/9/2026 | The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme,… | |
| Aplazada | Alta (8.5) | 0.47% | — | Wpforms ForminatorAI | 20/9/2026 | 21/9/2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an… | |
| Aplazada | Alta (7.2) | 0.39% | — | Mdmag Quill FormsAI | 19/9/2026 | 21/9/2026 | The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.8) | 3.9% | — | Gravityforms Gravity FormsAI | 19/9/2026 | 21/9/2026 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a… | |
| Pendiente de análisis | Media (6.1) | 0.20% | — | IBM Financial Transaction Manager FOR Swift Services FOR MultiplatformsAI | 18/9/2026 | 22/9/2026 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Aplazada | Media (4.9) | 0.51% | — | Nexforms NEX FormsAI | 18/9/2026 | 19/9/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Multi Uploader FOR Gravity FormsAI | 17/9/2026 | 19/9/2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload… | |
| Analizada | Alta (7.4) | 0.10% | — | Qualcomm Ar8035 FirmwareQualcomm C110100 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+148 | 17/9/2026 | 22/9/2026 | Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. | |
| Aplazada | Media (4.8) | 0.19% | — | Strategy11 Formidable FormsAI | 16/9/2026 | 16/9/2026 | The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing unauthenticated visitors to have arbitrary shortcodes, with attacker-chosen attributes, executed server-side… | |
| Aplazada | Media (4.3) | 0.14% | — | Strategy11 Formidable FormsAI | 16/9/2026 | 17/9/2026 | The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies on that identifier when deciding whether to strip HTML from stored entry values, allowing unauthenticated visitors to have markup rendered in the admin entry view… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Oracle FormsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Forms. While the… | |
| Aplazada | Alta (7.5) | 0.32% | — | Oracle FormsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Forms. Successful… |