Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

289 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.8)0.24%—Ninjaforms Ninja FormsAI6/8/202626/8/2026
The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a…
AplazadaAlta (7.1)0.25%—Wpmanageninja Ninja TablesAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
AplazadaAlta (7.2)0.53%—Wpmanageninja FluentsmtpAI6/8/202612/8/2026
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to insufficient input sanitization and output…
AplazadaAlta (8.7)0.35%—InvoiceninjaAILaravelAI5/8/202626/8/2026
InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.
AplazadaBaja (3.8)0.26%—Wpmanageninja Fluent SupportAI1/8/202626/8/2026
The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.
AplazadaMedia (4.9)0.51%—Ninjaforms Ninja FormsAI24/7/202624/7/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaMedia (6.4)0.34%—Wpmanageninja Fluent SupportAI24/7/202624/7/2026
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (5.3)0.33%—Wpsocialninja WP Social NinjaAI23/7/202623/7/2026
Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.
AplazadaMedia (5.3)0.33%—Wpmanageninja Ninja TablesAI23/7/202623/7/2026
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
AplazadaMedia (6.5)0.22%—Wpmanageninja Fluent SupportAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.
AplazadaCrítica (9.6)0.20%—Ninjaforms File Uploads ExtensionAI23/7/202623/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
AplazadaAlta (7.5)0.53%—Security Ninja PremiumAI23/7/202623/7/2026
The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor…
AplazadaAlta (8.7)0.58%—Ninjaforms Ninja FormsAI21/7/202622/7/2026
Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment totals by submitting values that do not match any configured option in ListSelect or ListRadio fields.…
AplazadaMedia (6.9)0.49%—Ninjaforms Ninja FormsAI21/7/202623/7/2026
Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a…
AplazadaAlta (7.1)0.44%—Ninjaforms Ninja FormsAI21/7/202623/7/2026
Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding…
AplazadaAlta (8.4)0.44%—Ninjaforms Ninja FormsAI21/7/202621/7/2026
Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers…
AplazadaCrítica (9.3)0.54%—Ninjaforms Ninja FormsAI21/7/202621/7/2026
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the…
AplazadaMedia (6.4)0.26%—Ninja Forms Excel ExportAI17/7/202617/7/2026
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due to the save_filter() AJAX handler storing the raw $_POST['filter'] array into a WordPress option via update_option() without any capability check, nonce verification, or…
AplazadaMedia (4.3)0.66%—Ninja Forms Excel ExportAI17/7/202617/7/2026
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to write .xls/.xlsx files to arbitrary…
AplazadaMedia (4.3)0.28%—Ninja Forms Excel ExportAI17/7/202617/7/2026
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level…
AplazadaMedia (5.3)0.35%—Ninjaforms Ninja Forms File UploadsAI3/7/20266/7/2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read all plugin debug log…
AplazadaAlta (7.5)0.60%—Ninjaforms Ninja Forms File UploadsAI2/7/20262/7/2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and including, 3.3.29. This is due to the get_files_for_attachment() function accepting a raw attacker-controlled 'files' array when the process() method returns early due to a…
AplazadaAlta (7.5)0.48%—Ninjaforms Ninja FormsAI1/7/20261/7/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers…
AplazadaMedia (5.3)0.29%—Invoiceninja Invoice NinjaAI30/6/202614/7/2026
Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthenticated attackers to redirect authenticated victims to attacker-controlled external URLs by injecting a malicious value into the intended query parameter. Attackers can craft a client login link with an…
AplazadaCrítica (9.8)0.56%💥 PoCIntegration FOR Activecampaign AND Contact Form 7 Wpforms Elementor Ninja FormsAI15/6/202617/6/2026
Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.
Orbitaley — Vulnerabilidades