Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.6% | 💥 Exploit | Redirection-for-contact-form7 Redirection FOR Contact Form 7 | 4/7/2022 | 17/6/2026 | The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (4.3) | 0.43% | — | Tiny Contact Form Project Tiny Contact Form | 27/6/2022 | 17/6/2026 | The Tiny Contact Form WordPress plugin through 0.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (4.8) | 0.59% | — | Form - Contact Form Project Form - Contact Form | 27/6/2022 | 17/6/2026 | The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Alta (7.5) | 1.2% | — | Very Simple Contact Form Project Very Simple Contact Form | 20/6/2022 | 17/6/2026 | The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for spam bots. | |
| Modificada | Media (5.4) | 0.83% | — | Bestwebsoft Contact Form | 16/6/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to… | |
| Modificada | Media (5.4) | 0.83% | — | Xyzscripts Contact Form Manager | 16/6/2022 | 17/6/2026 | A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Media (4.3) | 0.58% | — | Xyzscripts Contact Form Manager | 16/6/2022 | 17/6/2026 | A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Crítica (9.8) | 1.5% | — | Contact-form-with-messages-entry-management Project Contact-form-with-messages-entry-management | 2/6/2022 | 17/6/2026 | EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database. | |
| Modificada | Alta (7.5) | 8.8% | 💥 Exploit | Wpmet Metform Elementor Contact Form Builder | 10/5/2022 | 17/6/2026 | The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot,… | |
| Modificada | Media (6.5) | 1.1% | — | Material Design FOR Contact Form 7 Project Material Design FOR Contact Form 7 | 4/4/2022 | 17/6/2026 | The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in user (with roles as low as Subscriber) to set arbitrary options… | |
| Modificada | Media (5.4) | 14% | 💥 Exploit | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 28/3/2022 | 17/6/2026 | The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 1.7% | — | Contact Form Submissions Project Contact Form Submissions | 14/3/2022 | 17/6/2026 | The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker could perform Cross-Site Scripting attacks against admins viewing the malicious submission | |
| Modificada | Media (6.1) | 0.80% | — | WKI Idpay FOR Contact Form 7 | 14/3/2022 | 17/6/2026 | The IDPay for Contact Form 7 WordPress plugin through 2.1.2 does not sanitise and escape the idpay_error parameter before outputting it back in the page leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 1.0% | — | Plugin-planet Contact Form XFedoraproject Fedora | 11/3/2022 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4). | |
| Modificada | Alta (7.2) | 1.3% | — | Hotscot Contact Form | 7/3/2022 | 17/6/2026 | The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the sub_id parameter which not sanitised, escaped or validated before inserting to a SQL statement, leading to an SQL injection. | |
| Modificada | Media (4.9) | 1.3% | — | Wpeverest Contact Form | 28/2/2022 | 17/6/2026 | The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to download arbitrary files from the web server via a path traversal attack | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | Cf7skins Contact Form 7 Skins | 1/2/2022 | 17/6/2026 | The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 84% | — | Crmperks Contact Form Entries | 24/1/2022 | 17/6/2026 | The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry | |
| Modificada | Media (6.1) | 6.8% | 💥 Exploit | Crmperks Contact Form Entries | 24/1/2022 | 17/6/2026 | The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page | |
| Modificada | Media (6.1) | 1.2% | — | Themehunk Contact Form & Lead Form Elementor Builder | 27/12/2021 | 17/6/2026 | The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads | |
| Modificada | Alta (8.8) | 0.54% | — | Ciphercoin Contact Form 7 Database Addon | 22/12/2021 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.5.9). | |
| Modificada | Media (6.1) | 0.76% | — | Ciphercoin Contact Form 7 Database Addon | 22/12/2021 | 17/6/2026 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.6.1). | |
| Modificada | Media (4.3) | 0.38% | — | Contact Form Advanced Database Project Contact Form Advanced Database | 13/12/2021 | 17/6/2026 | The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead… | |
| Modificada | Media (4.8) | 0.62% | — | Reputeinfosystems Contact Form, Survey & Popup Form Plugin FOR Wordpress - Arforms Form Builder | 6/12/2021 | 17/6/2026 | The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed |