Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.1% | — | Formget Contact Form Integrated With Google Maps | 23/1/2020 | 17/6/2026 | The WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS | |
| Modificada | Media (6.1) | 1.6% | — | Fast Secure Contact Form Project Fast Secure Contact Form | 26/11/2019 | 17/6/2026 | The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS. | |
| Modificada | Crítica (9.8) | 1.9% | — | Awplife Contact Form Widget | 10/10/2019 | 17/6/2026 | The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php. | |
| Modificada | Crítica (9.8) | 2.0% | — | Rocklobster Contact Form 7 | 22/8/2019 | 17/6/2026 | The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type. | |
| Modificada | Media (6.1) | 0.92% | — | Bestwebsoft Contact Form | 22/8/2019 | 17/6/2026 | The contact-form-plugin plugin before 3.3.5 for WordPress has XSS. | |
| Modificada | Crítica (9.8) | 1.8% | — | Codepeople Booking Calendar Contact Form | 21/8/2019 | 17/6/2026 | The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection. | |
| Modificada | Media (6.1) | 0.91% | — | Codepeople Booking Calendar Contact Form | 21/8/2019 | 17/6/2026 | The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.94% | — | Codepeople CP Contact Form With Paypal | 15/8/2019 | 17/6/2026 | The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition. | |
| Modificada | Alta (8.8) | 0.68% | — | Codepeople Contact Form Email | 13/8/2019 | 17/6/2026 | The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF. | |
| Modificada | Media (6.1) | 0.92% | — | Codepeople Contact Form Email | 13/8/2019 | 17/6/2026 | The contact-form-to-email plugin before 1.2.66 for WordPress has XSS. | |
| Modificada | Media (6.1) | 1.5% | 💥 Exploit | Bestwebsoft Contact Form TO DB | 13/8/2019 | 17/6/2026 | The contact-form-to-db plugin before 1.5.7 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 1.5% | 💥 Exploit | Bestwebsoft Contact Form | 13/8/2019 | 17/6/2026 | The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 1.5% | 💥 Exploit | Bestwebsoft Contact Form Multi | 13/8/2019 | 17/6/2026 | The contact-form-multi plugin before 1.2.1 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 0.92% | — | Mediaburst Contact Form 7 - Clockwork SMS | 13/8/2019 | 17/6/2026 | The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.92% | — | Bestwebsoft Contact Form | 13/8/2019 | 17/6/2026 | The contact-form-plugin plugin before 4.0.2 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.92% | — | Bestwebsoft Contact Form | 13/8/2019 | 17/6/2026 | The contact-form-plugin plugin before 3.96 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.92% | — | Bestwebsoft Contact Form | 13/8/2019 | 17/6/2026 | The contact-form-plugin plugin before 3.52 for WordPress has XSS. | |
| Modificada | Media (5.4) | 0.80% | — | Codepeople CP Contact Form With Paypal | 9/8/2019 | 17/6/2026 | The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter. | |
| Modificada | Alta (8.8) | 1.1% | — | Web-dorado Contact Form | 29/4/2019 | 17/6/2026 | The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized. | |
| Modificada | Media (6.1) | 1.4% | — | Codepeople Contact Form Email | 10/3/2019 | 17/6/2026 | The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area." | |
| Modificada | Crítica (9.6) | 7.3% | 💥 Exploit | Contact-form-7-to-database-extension Project Contact-form-7-to-database-extension | 4/4/2018 | 17/6/2026 | CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form. | |
| Modificada | Media (6.1) | 0.95% | — | Mediaburst Booking Calendar SMSMediaburst Clockwork SMS NotficationsMediaburst Contact Form 7 SMSMediaburst Fast Secure Contact Form SMS+4 | 20/12/2017 | 17/6/2026 | The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2,… | |
| Modificada | Media (6.1) | 1.2% | — | Formget Easy Contact Form Solution | 6/10/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Easy Contact Form Solution plugin before 1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value parameter in a master_response action to wp-admin/admin-ajax.php. | |
| Modificada | Alta (7.2) | 2.0% | — | Cfpaypal CP Contact Form With Paypal | 30/9/2017 | 17/6/2026 | The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has SQL injection via the cp_contactformpp_id parameter to cp_contactformpp.php. | |
| Modificada | Alta (8.8) | 1.0% | — | Codepeople CP Contact Form With Paypal | 30/9/2017 | 17/6/2026 | The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php. |