Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1181 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.55% | — | Stedb Corp Stedb FormsAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in STEdb Corp. STEdb Forms stedb-forms allows SQL Injection.This issue affects STEdb Forms: from n/a through <= 1.0.4. | |
| Aplazada | Media (5.3) | 0.28% | — | Fluentforms Fluent FormsAI | 22/3/2025 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This… | |
| Aplazada | Media (5.3) | 0.39% | — | Nexweb NEX FormsAI | 12/3/2025 | 17/6/2026 | The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.8.1 via file uploads due to insufficient directory listing prevention and lack of randomization of file names. This makes it possible for… | |
| Analizada | Baja (2.7) | 0.33% | — | Convert Forms Project Convert Forms | 5/3/2025 | 17/6/2026 | A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the submission management area in backend. | |
| Aplazada | Alta (7.1) | 0.39% | — | Rebrandpress Rebrand Fluent FormsAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rebrandpress Rebrand Fluent Forms rebrand-fluent-forms allows Reflected XSS.This issue affects Rebrand Fluent Forms: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.54% | — | Alex Volkov WAH FormsAI | 3/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Alex Volkov WAH Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WAH Forms: from n/a through 1.0. | |
| Analizada | Media (5.4) | 0.25% | — | Wpmudev Forminator Forms | 27/2/2025 | 17/6/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider template data in all versions up to, and including, 1.39.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Crítica (9.8) | 29% | — | Wpeverest Everest Forms | 25/2/2025 | 17/6/2026 | The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format' method of the EVF_Form_Fields_Upload class in all versions up to, and including,… | |
| Analizada | Media (5.4) | 0.25% | — | Themekraft Buddyforms | 22/2/2025 | 17/6/2026 | The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buddyforms_nav' shortcode in all versions up to, and including, 2.8.15 due to insufficient input sanitization and… | |
| Aplazada | Media (6.4) | 0.42% | — | YayformsAI | 19/2/2025 | 17/6/2026 | The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yayforms' shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Modificada | Crítica (9.8) | 1.4% | — | Keap Official OPT IN Forms | 18/2/2025 | 17/6/2026 | The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be… | |
| Analizada | Media (6.1) | 0.38% | — | Kainex Wise Forms | 17/2/2025 | 17/6/2026 | The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks via malicious form submissions. | |
| Analizada | Media (4.8) | 0.33% | — | Wpmudev Forminator Forms | 14/2/2025 | 17/6/2026 | The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Baja (3.5) | 0.34% | — | Wpeverest Everest Forms | 13/2/2025 | 17/6/2026 | The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Crítica (9.8) | 0.40% | — | Progress Telerik UI FOR Winforms | 12/2/2025 | 17/6/2026 | In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory. | |
| Analizada | Media (5.3) | 0.42% | — | Vividcolorsjp Aforms Eats | 12/2/2025 | 17/6/2026 | The AForms Eats plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.3.1. This is due the /vendor/aura/payload-interface/phpunit.php file being publicly accessible and displaying error messages. This makes it possible for unauthenticated attackers to retrieve the full path… | |
| Analizada | Media (5.4) | 0.39% | — | Wpforms | 4/2/2025 | 17/6/2026 | The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fieldHTML’ parameter in all versions up to, and including, 1.9.3.1 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Alta (7.1) | 0.32% | — | Wpgear Import Excel TO Gravity FormsAIGravityforms Gravity FormsAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpgear Import Excel to Gravity Forms gf-excel-import allows Reflected XSS.This issue affects Import Excel to Gravity Forms: from n/a through <= 1.18. | |
| Aplazada | Alta (7.1) | 0.33% | — | Bannersky BSK Forms ValidationAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bannersky BSK Forms Validation bsk-gravity-forms-custom-validation allows Reflected XSS.This issue affects BSK Forms Validation: from n/a through <= 1.7. | |
| Analizada | Media (5.3) | 0.39% | — | Cimatti Wordpress Contact Forms | 1/2/2025 | 17/6/2026 | The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the accua_forms_download_submitted_file() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to download other user… | |
| Analizada | Media (6.1) | 0.32% | — | Wpmudev Forminator Forms | 31/1/2025 | 17/6/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the title parameter in all versions up to, and including, 1.38.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.3) | 0.55% | — | Pirateforms Contact Form SmtpAI | 30/1/2025 | 17/6/2026 | The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.6.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This… | |
| Analizada | Media (5.4) | 0.31% | — | Ninjaforms Ninja Forms | 30/1/2025 | 17/6/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.25% | — | Crmperks WP Dynamics CRM FOR Contact Form 7AICrmperks WP Dynamics CRM FOR WpformsAICrmperks WP Dynamics CRM FOR ElementorAICrmperks WP Dynamics CRM FOR FormidableAI+1 | 27/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-dynamics-crm allows Reflected XSS.This issue affects WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable… | |
| Aplazada | Crítica (9) | 0.53% | — | Sh1zen Multi Uploader FOR Gravity FormsAIGravityforms Gravity FormsAI | 22/1/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in sh1zen Multi Uploader for Gravity Forms gf-multi-uploader allows Upload a Web Shell to a Web Server.This issue affects Multi Uploader for Gravity Forms: from n/a through <= 1.1.3. |