Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

573 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.63%—Contact Form With Captcha Project Contact Form With Captcha29/11/202117/6/2026
The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php file during contact form submission, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.6.2.
ModificadaMedia (4.8)0.62%—Codepeople Contact Form Email17/11/202117/6/2026
The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the name parameter found in the ~/trunk/cp-admin-int-list.inc.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to…
ModificadaMedia (4.8)0.62%—Cimatti Contact Forms25/10/202117/6/2026
The WordPress Contact Forms by Cimatti WordPress plugin before 1.4.12 does not sanitise and escape the Form Title before outputting it in some admin pages. which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
ModificadaMedia (4.8)0.62%—Ninjaforms Contact Form25/10/202117/6/2026
The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (8.8)0.72%—Contact Form 7 Captcha Project Contact Form 7 Captcha23/8/202117/6/2026
The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored Cross-Site Scripting issue.
ModificadaAlta (8.8)2.6%—Fluentforms Contact Form7/7/202117/6/2026
The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions
ModificadaMedia (6.3)0.73%—Querysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s settings, wpcf7r_add_action to add actions to a…
ModificadaMedia (4.3)0.66%—Querysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site.
ModificadaAlta (8.8)2.0%—Querysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects.
ModificadaMedia (6.5)0.83%—Querysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository.
ModificadaAlta (7.5)7.4%💥 ExploitQuerysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.
ModificadaMedia (5.4)4.7%💥 ExploitMooveagency Contact Form Check Tester6/5/202117/6/2026
The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any registered user, such as subscriber, can leave an XSS payload in the plugin settings, which will be triggered by any user visiting them, and…
ModificadaMedia (6.1)16%💥 ExploitSupsystic Contact Form5/5/202117/6/2026
The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
ModificadaMedia (5.4)0.63%—Easy Contact Form PRO Project Easy Contact Form PRO5/4/202117/6/2026
The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subject, Email Recipient, etc) when creating or editing a form, leading to an authenticated (author+) stored cross-site scripting issue. This could allow medium privilege accounts (such as author and…
ModificadaAlta (8.8)0.59%—Rocklobster Contact Form 75/4/202117/6/2026
Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style WordPress plugin through 3.1.9. If an attacker successfully tricked a site’s administrator into clicking a link or…
ModificadaAlta (7.8)1.2%—Ciphercoin Contact Form 7 Database Addon18/3/202117/6/2026
Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.
ModificadaMedia (4.8)0.65%—Constantcontact Constant Contact Forms18/3/202117/6/2026
Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript code or HTML in posts where the malicious form is embed.
ModificadaAlta (7.2)1.5%—Contact Form Submissions Project Contact Form Submissions18/3/202117/6/2026
Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf7_contact_form GET parameter when submitting a filter request as a high privilege user (admin+)
ModificadaMedia (6.5)0.91%—Sean-barton Elementor Contact Form DB12/1/202117/6/2026
The Elementor Contact Form DB plugin before 1.6 for WordPress allows CSRF via backend admin pages.
ModificadaCrítica (10)89%💥 PoCRocklobster Contact Form 717/12/202017/6/2026
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
ModificadaCrítica (9.8)79%💥 ExploitCodedropz Drag AND Drop Multiple File Upload - Contact Form 78/6/202017/6/2026
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
ModificadaMedia (5.4)0.71%—Contact-form-7-datepicker Project Contact-form-7-datepicker7/4/202017/6/2026
Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minimal permissions to save arbitrary JavaScript to the plugin's settings via the unprotected wp_ajax_cf7dp_save_settings AJAX action and the ui_theme parameter. If an administrator creates or modifies a…
ModificadaMedia (5.4)4.4%💥 ExploitWpforms Contact Form24/3/202017/6/2026
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.
ModificadaMedia (5.3)3.1%—Creative-solutions Creative Contact Form4/3/202017/6/2026
An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploaded attachments via the creativecontactform_upload parameter. An attacker could exploit this vulnerability with the "Send…
ModificadaCrítica (9.8)92%💥 ExploitCreative-solutions Creative Contact FormJquery File Upload Project Jquery File Upload8/2/202017/6/2026
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by…
Orbitaley — Vulnerabilidades