Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

573 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.1%—Formget Contact Form Integrated With Google Maps23/1/202017/6/2026
The WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS
ModificadaMedia (6.1)1.6%—Fast Secure Contact Form Project Fast Secure Contact Form26/11/201917/6/2026
The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS.
ModificadaCrítica (9.8)1.9%—Awplife Contact Form Widget10/10/201917/6/2026
The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.
ModificadaCrítica (9.8)2.0%—Rocklobster Contact Form 722/8/201917/6/2026
The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.
ModificadaMedia (6.1)0.92%—Bestwebsoft Contact Form22/8/201917/6/2026
The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.
ModificadaCrítica (9.8)1.8%—Codepeople Booking Calendar Contact Form21/8/201917/6/2026
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
ModificadaMedia (6.1)0.91%—Codepeople Booking Calendar Contact Form21/8/201917/6/2026
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
ModificadaMedia (6.1)0.94%—Codepeople CP Contact Form With Paypal15/8/201917/6/2026
The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
ModificadaAlta (8.8)0.68%—Codepeople Contact Form Email13/8/201917/6/2026
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
ModificadaMedia (6.1)0.92%—Codepeople Contact Form Email13/8/201917/6/2026
The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
ModificadaMedia (6.1)1.5%💥 ExploitBestwebsoft Contact Form TO DB13/8/201917/6/2026
The contact-form-to-db plugin before 1.5.7 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)1.5%💥 ExploitBestwebsoft Contact Form13/8/201917/6/2026
The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)1.5%💥 ExploitBestwebsoft Contact Form Multi13/8/201917/6/2026
The contact-form-multi plugin before 1.2.1 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)0.92%—Mediaburst Contact Form 7 - Clockwork SMS13/8/201917/6/2026
The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS.
ModificadaMedia (6.1)0.92%—Bestwebsoft Contact Form13/8/201917/6/2026
The contact-form-plugin plugin before 4.0.2 for WordPress has XSS.
ModificadaMedia (6.1)0.92%—Bestwebsoft Contact Form13/8/201917/6/2026
The contact-form-plugin plugin before 3.96 for WordPress has XSS.
ModificadaMedia (6.1)0.92%—Bestwebsoft Contact Form13/8/201917/6/2026
The contact-form-plugin plugin before 3.52 for WordPress has XSS.
ModificadaMedia (5.4)0.80%—Codepeople CP Contact Form With Paypal9/8/201917/6/2026
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter.
ModificadaAlta (8.8)1.1%—Web-dorado Contact Form29/4/201917/6/2026
The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.
ModificadaMedia (6.1)1.4%—Codepeople Contact Form Email10/3/201917/6/2026
The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area."
ModificadaCrítica (9.6)7.3%💥 ExploitContact-form-7-to-database-extension Project Contact-form-7-to-database-extension4/4/201817/6/2026
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.
ModificadaMedia (6.1)0.95%—Mediaburst Booking Calendar SMSMediaburst Clockwork SMS NotficationsMediaburst Contact Form 7 SMSMediaburst Fast Secure Contact Form SMS+420/12/201717/6/2026
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2,…
ModificadaMedia (6.1)1.2%—Formget Easy Contact Form Solution6/10/201717/6/2026
Cross-site scripting (XSS) vulnerability in the Easy Contact Form Solution plugin before 1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value parameter in a master_response action to wp-admin/admin-ajax.php.
ModificadaAlta (7.2)2.0%—Cfpaypal CP Contact Form With Paypal30/9/201717/6/2026
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has SQL injection via the cp_contactformpp_id parameter to cp_contactformpp.php.
ModificadaAlta (8.8)1.0%—Codepeople CP Contact Form With Paypal30/9/201717/6/2026
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php.
Orbitaley — Vulnerabilidades