Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

573 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.6%💥 ExploitRedirection-for-contact-form7 Redirection FOR Contact Form 74/7/202217/6/2026
The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting
ModificadaMedia (4.3)0.43%—Tiny Contact Form Project Tiny Contact Form27/6/202217/6/2026
The Tiny Contact Form WordPress plugin through 0.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaMedia (4.8)0.59%—Form - Contact Form Project Form - Contact Form27/6/202217/6/2026
The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaAlta (7.5)1.2%—Very Simple Contact Form Project Very Simple Contact Form20/6/202217/6/2026
The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for spam bots.
ModificadaMedia (5.4)0.83%—Bestwebsoft Contact Form16/6/202217/6/2026
A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to…
ModificadaMedia (5.4)0.83%—Xyzscripts Contact Form Manager16/6/202217/6/2026
A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
ModificadaMedia (4.3)0.58%—Xyzscripts Contact Form Manager16/6/202217/6/2026
A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
ModificadaCrítica (9.8)1.5%—Contact-form-with-messages-entry-management Project Contact-form-with-messages-entry-management2/6/202217/6/2026
EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database.
ModificadaAlta (7.5)8.8%💥 ExploitWpmet Metform Elementor Contact Form Builder10/5/202217/6/2026
The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot,…
ModificadaMedia (6.5)1.1%—Material Design FOR Contact Form 7 Project Material Design FOR Contact Form 74/4/202217/6/2026
The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in user (with roles as low as Subscriber) to set arbitrary options…
ModificadaMedia (5.4)14%💥 ExploitCodedropz Drag AND Drop Multiple File Upload - Contact Form 728/3/202217/6/2026
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue
ModificadaMedia (6.1)1.7%—Contact Form Submissions Project Contact Form Submissions14/3/202217/6/2026
The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker could perform Cross-Site Scripting attacks against admins viewing the malicious submission
ModificadaMedia (6.1)0.80%—WKI Idpay FOR Contact Form 714/3/202217/6/2026
The IDPay for Contact Form 7 WordPress plugin through 2.1.2 does not sanitise and escape the idpay_error parameter before outputting it back in the page leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)1.0%—Plugin-planet Contact Form XFedoraproject Fedora11/3/202217/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).
ModificadaAlta (7.2)1.3%—Hotscot Contact Form7/3/202217/6/2026
The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the sub_id parameter which not sanitised, escaped or validated before inserting to a SQL statement, leading to an SQL injection.
ModificadaMedia (4.9)1.3%—Wpeverest Contact Form28/2/202217/6/2026
The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to download arbitrary files from the web server via a path traversal attack
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaMedia (6.1)2.1%💥 ExploitCf7skins Contact Form 7 Skins1/2/202217/6/2026
The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)84%—Crmperks Contact Form Entries24/1/202217/6/2026
The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry
ModificadaMedia (6.1)6.8%💥 ExploitCrmperks Contact Form Entries24/1/202217/6/2026
The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page
ModificadaMedia (6.1)1.2%—Themehunk Contact Form & Lead Form Elementor Builder27/12/202117/6/2026
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads
ModificadaAlta (8.8)0.54%—Ciphercoin Contact Form 7 Database Addon22/12/202117/6/2026
Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.5.9).
ModificadaMedia (6.1)0.76%—Ciphercoin Contact Form 7 Database Addon22/12/202117/6/2026
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.6.1).
ModificadaMedia (4.3)0.38%—Contact Form Advanced Database Project Contact Form Advanced Database13/12/202117/6/2026
The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead…
ModificadaMedia (4.8)0.62%—Reputeinfosystems Contact Form, Survey & Popup Form Plugin FOR Wordpress - Arforms Form Builder6/12/202117/6/2026
The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed