Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
289 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.24% | — | Ninjaforms Ninja FormsAI | 6/8/2026 | 26/8/2026 | The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpmanageninja Ninja TablesAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. | |
| Aplazada | Alta (7.2) | 0.53% | — | Wpmanageninja FluentsmtpAI | 6/8/2026 | 12/8/2026 | The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to insufficient input sanitization and output… | |
| Aplazada | Alta (8.7) | 0.35% | — | InvoiceninjaAILaravelAI | 5/8/2026 | 26/8/2026 | InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization. | |
| Aplazada | Baja (3.8) | 0.26% | — | Wpmanageninja Fluent SupportAI | 1/8/2026 | 26/8/2026 | The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope. | |
| Aplazada | Media (4.9) | 0.51% | — | Ninjaforms Ninja FormsAI | 24/7/2026 | 24/7/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (6.4) | 0.34% | — | Wpmanageninja Fluent SupportAI | 24/7/2026 | 24/7/2026 | The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.33% | — | Wpsocialninja WP Social NinjaAI | 23/7/2026 | 23/7/2026 | Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions. | |
| Aplazada | Media (5.3) | 0.33% | — | Wpmanageninja Ninja TablesAI | 23/7/2026 | 23/7/2026 | Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpmanageninja Fluent SupportAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions. | |
| Aplazada | Crítica (9.6) | 0.20% | — | Ninjaforms File Uploads ExtensionAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| Aplazada | Alta (7.5) | 0.53% | — | Security Ninja PremiumAI | 23/7/2026 | 23/7/2026 | The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor… | |
| Aplazada | Alta (8.7) | 0.58% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 22/7/2026 | Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment totals by submitting values that do not match any configured option in ListSelect or ListRadio fields.… | |
| Aplazada | Media (6.9) | 0.49% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 23/7/2026 | Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a… | |
| Aplazada | Alta (7.1) | 0.44% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 23/7/2026 | Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding… | |
| Aplazada | Alta (8.4) | 0.44% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 21/7/2026 | Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers… | |
| Aplazada | Crítica (9.3) | 0.54% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 21/7/2026 | Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the… | |
| Aplazada | Media (6.4) | 0.26% | — | Ninja Forms Excel ExportAI | 17/7/2026 | 17/7/2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due to the save_filter() AJAX handler storing the raw $_POST['filter'] array into a WordPress option via update_option() without any capability check, nonce verification, or… | |
| Aplazada | Media (4.3) | 0.66% | — | Ninja Forms Excel ExportAI | 17/7/2026 | 17/7/2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to write .xls/.xlsx files to arbitrary… | |
| Aplazada | Media (4.3) | 0.28% | — | Ninja Forms Excel ExportAI | 17/7/2026 | 17/7/2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level… | |
| Aplazada | Media (5.3) | 0.35% | — | Ninjaforms Ninja Forms File UploadsAI | 3/7/2026 | 6/7/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read all plugin debug log… | |
| Aplazada | Alta (7.5) | 0.60% | — | Ninjaforms Ninja Forms File UploadsAI | 2/7/2026 | 2/7/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and including, 3.3.29. This is due to the get_files_for_attachment() function accepting a raw attacker-controlled 'files' array when the process() method returns early due to a… | |
| Aplazada | Alta (7.5) | 0.48% | — | Ninjaforms Ninja FormsAI | 1/7/2026 | 1/7/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (5.3) | 0.29% | — | Invoiceninja Invoice NinjaAI | 30/6/2026 | 14/7/2026 | Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthenticated attackers to redirect authenticated victims to attacker-controlled external URLs by injecting a malicious value into the intended query parameter. Attackers can craft a client login link with an… | |
| Aplazada | Crítica (9.8) | 0.56% | 💥 PoC | Integration FOR Activecampaign AND Contact Form 7 Wpforms Elementor Ninja FormsAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. |