Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.35% | — | Gravity SmtpAI | 10/4/2026 | 17/6/2026 | The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to uninstall… | |
| Aplazada | Media (6.4) | 0.24% | — | Magicconversation Magic Conversation FOR Gravity FormsAI | 8/4/2026 | 25/7/2026 | The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'magic-conversation' shortcode in all versions up to, and including, 3.0.97 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (4.7) | 0.39% | — | Gravityforms Gravity FormsAI | 8/4/2026 | 24/7/2026 | The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This is due to the `GFCommon::send_json()` method outputting JSON-encoded data wrapped in HTML comment delimiters using… | |
| Aplazada | Media (6.1) | 0.38% | — | Gravityforms Gravity FormsAI | 8/4/2026 | 24/7/2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`) in all versions up to, and including, 2.9.30. This is due to the `get_value_entry_detail()` method in the `GF_Field_CreditCard` class outputting the card type value… | |
| Aplazada | Alta (7.5) | 2.2% | — | Gravity SmtpAI | 31/3/2026 | 17/6/2026 | The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor… | |
| Aplazada | Media (6.4) | 0.26% | — | Gravityforms Gravity FormsAI | 11/3/2026 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a compound failure involving missing authorization on the `create_from_template` AJAX endpoint (allowing any authenticated user to create forms), insufficient input… | |
| Aplazada | Alta (7.1) | 0.19% | — | Zack Katz Icontact FOR Gravity FormsAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz iContact for Gravity Forms gravity-forms-icontact allows Reflected XSS.This issue affects iContact for Gravity Forms: from n/a through <= 1.3.2. | |
| Aplazada | Media (4.3) | 0.22% | — | Gravityforms Signature Add-onAI | 31/12/2025 | 28/9/2026 | Missing Authorization vulnerability in approveme Signature Add-On for Gravity Forms gravity-signature-forms-add-on allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Signature Add-On for Gravity Forms: from n/a through <= 1.8.6. | |
| Aplazada | Media (6.8) | 0.37% | — | Gravityforms Gravity FormsAI | 24/12/2025 | 17/6/2026 | The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path. | |
| Aplazada | Alta (8.5) | 0.15% | — | Cobian Backup GravityAI | 22/12/2025 | 17/6/2026 | Cobian Backup Gravity 11.2.0.582 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the CobianBackup11 service to inject malicious code that would execute with LocalSystem… | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Salesforce | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue affects WP Gravity Forms Salesforce: from n/a through <= 1.5.1. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Hubspot | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection.This issue affects WP Gravity Forms HubSpot: from n/a through <= 1.2.6. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Constant Contact Plugin | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contact allows Object Injection.This issue affects WP Gravity Forms Constant Contact Plugin: from n/a through <= 1.1.2. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Zoho CRM AND Bigin | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.9. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Insightly | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gravity Forms Insightly: from n/a through <= 1.1.6. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Freshdesk Plugin | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5. | |
| Aplazada | Alta (7.5) | 0.35% | — | Bplugins PDF FOR Gravity FormsAIGravityforms Gravity FormsAI | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Gravity Forms + Drag And Drop Template Builder pdf-for-gravity-forms allows Object Injection.This issue affects PDF for Gravity Forms + Drag And Drop Template Builder: from n/a through <= 6.5.0. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Multi Uploader FOR Gravity FormsAI | 12/12/2025 | 17/6/2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'plupload_ajax_delete_file' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the… | |
| Aplazada | Media (4.7) | 0.20% | — | Crmperks WP Gravity Forms FreshdeskAI | 9/12/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Phishing.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5. | |
| Aplazada | Alta (8.1) | 0.67% | — | Gravityforms Gravity FormsAI | 18/11/2025 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechanism in all versions up to, and including, 2.9.21.1. This is due to the extension blacklist not including .phar files, which can be uploaded through the chunked upload… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Gravityforms Gravity FormsAI | 7/11/2025 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Keap InfusionsoftAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows Object Injection.This issue affects WP Gravity Forms Keap/Infusionsoft: from n/a through <= 1.2.3. | |
| Aplazada | Alta (7.1) | 0.21% | — | Pluginscafe Range Slider Addon FOR Gravity FormsAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginsCafe Range Slider Addon for Gravity Forms range-slider-addon-for-gravity-forms allows Reflected XSS.This issue affects Range Slider Addon for Gravity Forms: from n/a through <= 1.1.6. | |
| Aplazada | Alta (7.5) | 0.52% | — | Daman Jeet Real Time Validation FOR Gravity FormsAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Daman Jeet Real Time Validation for Gravity Forms real-time-validation-for-gravity-forms allows PHP Local File Inclusion.This issue affects Real Time Validation for Gravity Forms: from n/a through… | |
| Aplazada | Media (4.7) | 0.22% | — | Crmperks WP Gravity Forms Zoho CRM AND BiginAI | 27/10/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Phishing.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.8. |