Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2676▼ 662 respecto a la semana anterior
Críticas / altas1264▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1181 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)0.60%—Basixonline Nex-forms25/12/202417/6/2026
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to SQL Injection via the 'search_params' parameter in all versions up to, and including, 8.7.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaAlta (8.5)0.40%—Powerformbuilder Power-forms-builderAI18/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PowerFormBuilder PowerFormBuilder power-forms-builder allows SQL Injection.This issue affects PowerFormBuilder: from n/a through <= 1.0.6.
AplazadaAlta (7.1)0.20%—Projectcaruso Flaming FormsAI16/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in jcaruso001 Flaming Forms flaming-forms allows Stored XSS.This issue affects Flaming Forms: from n/a through <= 1.0.1.
AnalizadaMedia (6.1)0.36%—Fluentforms Contact Form14/12/202417/6/2026
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping. This makes it possible for…
ModificadaAlta (8.8)0.71%—Mailmunch Mailchimp Forms13/12/202417/6/2026
Missing Authorization vulnerability in MailMunch MailChimp Forms by MailMunch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailChimp Forms by MailMunch: from n/a through 3.1.4.
ModificadaAlta (8.8)0.56%—Cimatti Wordpress Contact Forms13/12/202417/6/2026
Missing Authorization vulnerability in Cimatti Consulting Contact Forms by Cimatti allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Forms by Cimatti: from n/a through 1.5.7.
AplazadaMedia (4.3)0.47%—Constantcontact Constant Contact FormsAI13/12/202417/6/2026
Missing Authorization vulnerability in Constant Contact Constant Contact Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Constant Contact Forms: from n/a through 2.0.3.
ModificadaCrítica (9.8)0.52%—Strategy11 Formidable Forms13/12/202417/6/2026
Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Formidable Forms: from n/a through 5.5.4.
AnalizadaMedia (6.1)0.32%—Ninjaforms Ninja Forms12/12/202417/6/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
AplazadaMedia (6.4)0.37%—Cognito FormsAI12/12/202417/6/2026
The Cognito Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
AnalizadaMedia (6.5)0.73%—Wpforms10/12/202417/6/2026
The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
ModificadaMedia (6.1)0.33%—Reputeinfosystems Arforms Form Builder9/12/202417/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in reputeinfosystems ARForms Form Builder arforms-form-builder allows Code Injection.This issue affects ARForms Form Builder: from n/a through <= 1.7.1.
ModificadaMedia (5.4)0.45%—Reputeinfosystems Arforms9/12/202417/6/2026
Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.1.
ModificadaAlta (8.8)0.54%—Rednao Smart Forms9/12/202417/6/2026
Missing Authorization vulnerability in EDGARROJAS Smart Forms smart-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Forms: from n/a through <= 2.6.84.
AnalizadaMedia (6.1)0.37%—Fluentforms Contact Form9/12/202417/6/2026
The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AplazadaMedia (4.3)0.31%—SMS FOR Lead Capture FormsAI7/12/202417/6/2026
The SMS for Lead Capture Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_message() function in all versions up to, and including, 1.1.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete…
ModificadaAlta (7.7)0.55%—Reputeinfosystems Arforms6/12/20247/7/2026
Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms allows Path Traversal. This issue affects ARForms: from n/a before 7.0.2.
ModificadaAlta (7.2)0.61%—Basixonline Nex-forms6/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows SQL Injection.This issue affects NEX-Forms: from n/a through <= 8.7.8.
AplazadaMedia (6.3)0.46%—Pojo FormsAI6/12/202417/6/2026
The The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via form_preview_shortcode AJAX action in all versions up to, and including, 1.4.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…
AnalizadaMedia (5.4)0.22%—Convert Forms Project Convert Forms4/12/202417/6/2026
Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8.
AnalizadaCrítica (9.8)0.52%—Convert Forms Project Convert Forms4/12/202417/6/2026
Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.
AplazadaAlta (8.1)0.51%—RegistrationformsAI4/12/202417/6/2026
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.9. This is due to insufficient verification on the user…
ModificadaMedia (5.4)0.30%—Mightyforms4/12/202417/6/2026
The Contact Form, Survey & Form Builder – MightyForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mightyforms' shortcode in all versions up to, and including, 1.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaAlta (8.8)0.62%—FunnelformsAI4/12/202417/6/2026
The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.7.5.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level…
AplazadaMedia (6.1)0.35%—Campaign Monitor Forms BY Optin CATAI3/12/202417/6/2026
The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
Orbitaley — Vulnerabilidades