Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
8593 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (7.5) | 0.32% | — | Kiteworks Secure Data FormsAI | 30/9/2026 | 1/10/2026 | Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other… | |
| Pendiente de análisis | Baja (1.2) | 0.30% | — | Wikimedia Page FormsAI | 30/9/2026 | 30/9/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43. | |
| Aplazada | Alta (7.1) | 0.15% | — | Crocoblock JetformbuilderAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Cool Formkit LiteAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | HappyformsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions. | |
| Aplazada | Alta (7.2) | 0.40% | — | Themefic Ultimate Addons FOR Contact Form 7AI | 30/9/2026 | 30/9/2026 | Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. | |
| Aplazada | Alta (8.8) | 0.48% | — | Quantumcloud Conversational Forms FOR ChatbotAI | 30/9/2026 | 30/9/2026 | Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. | |
| Aplazada | Alta (7.1) | 0.28% | — | FormgentAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in FormGent <= 1.12.2 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Ninjaforms Ninja FormsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | |
| Analizada | Crítica (9.5) | 0.32% | — | Balbooa Forms | 29/9/2026 | 6/10/2026 | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component… | |
| Analizada | Alta (8.9) | 0.37% | — | Balbooa Forms | 29/9/2026 | 6/10/2026 | Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the… | |
| Analizada | Alta (8.6) | 0.32% | — | Balbooa Forms | 29/9/2026 | 6/10/2026 | Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A… | |
| Analizada | Media (6.9) | 0.37% | — | Balbooa Forms | 29/9/2026 | 6/10/2026 | Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and display names are trusted directly, introducing potential cross-session claiming, metadata… | |
| Analizada | Media (6.9) | 0.29% | — | Balbooa Forms | 29/9/2026 | 6/10/2026 | Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session… | |
| Aplazada | Alta (8.8) | 0.23% | — | Interprobe Information Technologies Qorela DCAI | 29/9/2026 | 29/9/2026 | Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse. This issue affects Qorela DC: from 1.6.1-RC29 before v1.6.2. | |
| Aplazada | Alta (7.2) | 0.19% | — | Htplugins HT Contact FormAI | 29/9/2026 | 30/9/2026 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.1) | 0.15% | — | Enocta PlatformAI | 28/9/2026 | 28/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows XSS Targeting HTML Attributes. This issue affects Enocta Platform: through 2026-09-28. | |
| Aplazada | Alta (8.1) | 0.26% | — | Enocta Educational Technologies INC Enocta PlatformAI | 28/9/2026 | 28/9/2026 | Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows Exploitation of Trusted Identifiers. This issue affects Enocta Platform: through 2026-09-28. | |
| Aplazada | Media (6.1) | 0.15% | — | Rolantis Information Technologies AgentisAI | 28/9/2026 | 28/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. Agentis allows XSS Targeting HTML Attributes. This issue affects Agentis: from 4.44 before 4.6. | |
| Aplazada | Media (6.5) | 0.18% | — | Wpforms LiteAI | 28/9/2026 | 28/9/2026 | The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public… | |
| Pendiente de análisis | Alta (7.4) | 0.21% | — | Parseplatform Parse ServerAI | 27/9/2026 | 30/9/2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, Weibo) verify the client's authorization code with the external provider on signup… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Ultra Addons FOR Contact Form 7AI | 26/9/2026 | 28/9/2026 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the… | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Parseplatform Parse ServerAI | 26/9/2026 | 30/9/2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller identity: the subscriber's roles are not resolved, and when a subscription does not supply its own… | |
| Pendiente de análisis | Alta (8.7) | 0.36% | — | Parseplatform Parse ServerAI | 26/9/2026 | 30/9/2026 | Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields before using them to build database queries. An unauthenticated… | |
| Aplazada | Media (6) | 0.35% | — | Tduck Survey FormAI | 25/9/2026 | 29/9/2026 | TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access deleted form submissions. Attackers can read orphaned submission data including personal information by providing a known dataId to… |