Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.39% | — | Abandoned Contact Form 7AI | 16/6/2026 | 17/6/2026 | The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capability check and missing nonce validation in the action__remove_abandoned() function, which is registered to both the wp_ajax_remove_abandoned and… | |
| Aplazada | Crítica (9.8) | 0.56% | 💥 PoC | Integration FOR Activecampaign AND Contact Form 7 Wpforms Elementor Ninja FormsAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Integration FOR Mailchimp AND Contact Form 7AI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Integration FOR Contact Form 7 HubspotAI | 15/6/2026 | 8/7/2026 | Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Integration FOR Contact Form 7 AND Constant ContactAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Contact Form 7 Drag AND Drop Multiple File UploadAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.7 versions. | |
| Aplazada | Alta (8.6) | 0.64% | — | Contact Form Extender FOR DiviAI | 15/6/2026 | 17/6/2026 | Unauthenticated Arbitrary File Deletion in Contact Form Extender for Divi – Save Entries, File Upload & Country Code Field <= 1.0.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Itpathsolutions Contact Form TO ANY APIAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API <= 3.0.3 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Contact Form 7AI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions. | |
| Aplazada | Media (5.1) | 0.22% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin options and inject malicious scripts by failing to verify user privileges and sanitize input parameters. Attackers with subscriber-level accounts… | |
| Aplazada | Alta (8.8) | 0.24% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shortcode function that fails to sanitize the calendar parameter before using it in database queries. Attackers can inject SQL commands through the calendar shortcode parameter to execute arbitrary SQL… | |
| Aplazada | Alta (8.8) | 0.30% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send requests to the admin-ajax.php endpoint with the action parameter… | |
| Aplazada | Media (5.4) | 0.18% | — | Themehunk Contact Form AND Lead Form Elementor BuilderAI | 11/6/2026 | 26/9/2026 | Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Contact Form & Lead Form Elementor Builder: from n/a through 1.8.4. | |
| Aplazada | Media (4.4) | 0.34% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 6/6/2026 | 23/7/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings in all versions up to, and including, 1.3.9.7 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.51% | — | Freshsales Contact Form 7 IntegrationAI | 6/6/2026 | 23/7/2026 | The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Submission Data in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.1) | 0.89% | — | WD Contact FormAI | 4/6/2026 | 22/7/2026 | Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanitized action parameters. Attackers can craft malicious forms targeting the admin-ajax.php endpoint with directory… | |
| Aplazada | Media (5.3) | 0.25% | — | Contact Form 7 Paypal Stripe ADD ONAI | 29/5/2026 | 21/7/2026 | The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Although `cf7pp_paypal_ipn_handler()` correctly validates IPN authenticity by posting back to PayPal with… | |
| Aplazada | Alta (7.2) | 0.51% | — | HT Contact FormAI | 28/5/2026 | 17/6/2026 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'file_upload' parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (8.1) | 0.37% | — | WP Contact Form 7 DB HandlerAI | 28/5/2026 | 17/6/2026 | The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce verification in the process_bulk_action() function, the nonce check is only… | |
| Aplazada | Alta (7.1) | 0.25% | — | HT Plugins HT Contact Form 7AI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows Stored XSS.This issue affects HT Contact Form 7: from n/a through <= 2.8.2. | |
| Aplazada | Alta (7.1) | 0.21% | — | Web-dorado Contact Form MakerAI | 23/5/2026 | 23/7/2026 | WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through the FormMakerSQLMapping and generete_csv_fmc AJAX actions. Attackers can inject malicious SQL code via the 'name' and 'search_labels' parameters to extract… | |
| Aplazada | Media (4.3) | 0.36% | — | Coinbase Commerce FOR Contact Form 7AI | 12/5/2026 | 17/6/2026 | The Coinbase Commerce for Contact Form 7 plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.1.2. This is due to a missing capability check and missing nonce verification in the save_settings() function, which is registered on the admin_post_cccf7_save_settings hook. This… | |
| Aplazada | Media (5.1) | 0.19% | — | Wordpress International SMS FOR Contact Form 7 IntegrationAI | 10/5/2026 | 24/7/2026 | WordPress International SMS for Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter of the admin settings interface. Attackers can inject malicious scripts through the page parameter in class-sms-log-display.php to execute arbitrary JavaScript in… | |
| Aplazada | Media (5.1) | 0.21% | — | Wordpress Contact Form BuilderAI | 10/5/2026 | 24/7/2026 | WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary… | |
| Aplazada | Media (5.1) | 0.19% | — | Contact Form TO EmailAI | 10/5/2026 | 25/7/2026 | Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name field. Attackers can craft form names containing JavaScript code that executes when other logged-in users access the form… |