Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.34% | — | Bestwebsoft Google CaptchaAI | 27/1/2025 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in bestwebsoft Google Captcha google-captcha allows Identity Spoofing.This issue affects Google Captcha: from n/a through <= 1.78. | |
| Aplazada | Alta (7.1) | 0.39% | — | Osolwordpress Customizable-captcha-and-contact-us-formAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osolwordpress Customizable Captcha and Contact Us customizable-captcha-and-contact-us-form allows Reflected XSS.This issue affects Customizable Captcha and Contact Us: from n/a through <= 1.0.2. | |
| Aplazada | Alta (7.1) | 0.17% | — | Uosiu Secure CaptchaAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in uosiu Secure CAPTCHA secure-captcha allows Stored XSS.This issue affects Secure CAPTCHA: from n/a through <= 1.2. | |
| Aplazada | Media (5.3) | 0.35% | — | Webfactoryltd Advanced Google RecaptchaAI | 24/12/2024 | 17/6/2026 | The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, 1.25. This is due to the plugin not utilizing a strong unique key when generating an unblock request. This makes it possible for unauthenticated attackers to unblock their IP after being locked out… | |
| Aplazada | Media (6.5) | 0.62% | — | Wppal Easy CaptchaAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in wppal Easy Captcha allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Captcha: from n/a through 1.0. | |
| Aplazada | Media (4.3) | 0.47% | — | Billminozzi RecaptchaAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Bill Minozzi reCAPTCHA for all allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects reCAPTCHA for all: from n/a through 1.22. | |
| Aplazada | Media (6.1) | 0.22% | — | SKT NurcaptchaAI | 26/11/2024 | 17/6/2026 | The Skt NURCaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing or incorrect nonce validation in the skt-nurc-admin.php file. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts… | |
| Analizada | Media (6.1) | 0.43% | — | Wedevs Recaptcha Integration | 2/11/2024 | 17/6/2026 | The ReCaptcha Integration for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Alta (7.1) | 0.29% | — | Rafasashi Svg-captchaAI | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rafasashi SVG Captcha svg-captcha allows Reflected XSS.This issue affects SVG Captcha: from n/a through <= 1.0.11. | |
| Analizada | Media (6.1) | 0.32% | — | Techbanker Captcha Bank | 4/10/2024 | 17/6/2026 | The WordPress Captcha Plugin by Captcha Bank plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.0.36. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Media (6.1) | 0.70% | — | Dotsquares Contact Form 7 Math Captcha | 26/9/2024 | 17/6/2026 | The Contact Form 7 Math Captcha WordPress plugin through 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users. | |
| Aplazada | Media (5.9) | 0.28% | — | Wedevs Recaptcha Integration FOR WordpressAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs ReCaptcha Integration for WordPress wp-recaptcha-integration allows DOM-Based XSS.This issue affects ReCaptcha Integration for WordPress: from n/a through <= 1.2.7. | |
| Aplazada | Media (5.3) | 0.55% | — | Friendlycaptcha OfficialAITypo3AITypo3 FormAI | 21/6/2024 | 17/6/2026 | An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, allowing a remote user to bypass the captcha check. This only affects the captcha integration for the… | |
| Aplazada | Media (5.3) | 0.35% | — | Webfactoryltd Captcha CodeAI | 4/6/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in WebFactory Ltd Captcha Code allows Functionality Bypass.This issue affects Captcha Code: from n/a through 2.9. | |
| Aplazada | Media (5.3) | 0.38% | — | Nitinrathod WP Forms Puzzle CaptchaAI | 4/6/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Functionality Bypass.This issue affects WP Forms Puzzle Captcha: from n/a through 4.1. | |
| Aplazada | Media (5.3) | 0.40% | — | Forge12 Interactive Gmbh Captcha Honeypot FOR Contact Form 7AI | 4/6/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Forge12 Interactive GmbH Captcha/Honeypot for Contact Form 7 allows Functionality Bypass.This issue affects Captcha/Honeypot for Contact Form 7: from n/a through 1.11.3. | |
| Aplazada | Media (5.3) | 0.51% | — | Devnath Verma WP CaptchaAI | 4/6/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Devnath verma WP Captcha allows Functionality Bypass.This issue affects WP Captcha: from n/a through 2.0.0. | |
| Aplazada | Media (6.5) | 0.40% | — | Cartpauj Register CaptchaAI | 4/6/2024 | 17/6/2026 | : Improper Control of Interaction Frequency vulnerability in cartpauj Cartpauj Register Captcha allows Functionality Misuse.This issue affects Cartpauj Register Captcha: from n/a through 1.0.02. | |
| Aplazada | Media (5.3) | 0.38% | — | Bestwebsoft CaptchaAI | 17/5/2024 | 17/6/2026 | Guessable CAPTCHA vulnerability in BestWebSoft Captcha by BestWebSoft allows Functionality Bypass.This issue affects Captcha by BestWebSoft: from n/a through 5.2.0. | |
| Analizada | Media (4.7) | 0.27% | — | Bozdoz Recaptcha Jetpack | 14/5/2024 | 17/6/2026 | The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack. | |
| Analizada | Alta (8.8) | 0.38% | — | Bozdoz Recaptcha Jetpack | 14/5/2024 | 17/6/2026 | The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Aplazada | Media (6.4) | 0.33% | — | HcaptchaAI | 20/4/2024 | 17/6/2026 | The hCaptcha for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf7-hcaptcha shortcode in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Alta (7.1) | 0.33% | — | Bestwebsoft Captcha | 26/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contact Form With Captcha allows Reflected XSS.This issue affects Contact Form With Captcha: from n/a through 1.6.8. | |
| Modificada | Media (6.1) | 0.46% | — | Bestwebsoft Pluscaptcha | 26/12/2023 | 17/6/2026 | A vulnerability was found in PlusCaptcha Plugin up to 2.0.6 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 2.0.14 is able to address this issue. The patch is… | |
| Modificada | Media (5.3) | 0.30% | — | Mojotv Base64captcha | 11/12/2023 | 17/6/2026 | When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the function will always consider the Captcha to be correct. |