Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.51% | — | Salesmate Add-on FOR Gravity FormsAIGravityforms Gravity FormsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salesmate.io Salesmate Add-On for Gravity Forms gf-salesmate-add-on allows SQL Injection.This issue affects Salesmate Add-On for Gravity Forms: from n/a through <= 2.0.3. | |
| Aplazada | Media (5.3) | 0.42% | — | Salesmate Add-on FOR Gravity FormsAIGravityforms Gravity FormsAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Salesmate.io Salesmate Add-On for Gravity Forms gf-salesmate-add-on allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Salesmate Add-On for Gravity Forms: from n/a through <= 2.0.3. | |
| Aplazada | Alta (7.1) | 0.32% | — | Wpgear Import Excel TO Gravity FormsAIGravityforms Gravity FormsAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpgear Import Excel to Gravity Forms gf-excel-import allows Reflected XSS.This issue affects Import Excel to Gravity Forms: from n/a through <= 1.18. | |
| Aplazada | Crítica (9) | 0.53% | — | Sh1zen Multi Uploader FOR Gravity FormsAIGravityforms Gravity FormsAI | 22/1/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in sh1zen Multi Uploader for Gravity Forms gf-multi-uploader allows Upload a Web Shell to a Web Server.This issue affects Multi Uploader for Gravity Forms: from n/a through <= 1.1.3. | |
| Aplazada | Media (5.4) | 0.29% | — | Gravityforms Gravity FormsAI | 17/1/2025 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter in versions 2.9.0.1 up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (7.2) | 0.32% | — | Gravityforms Gravity FormsAI | 17/1/2025 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Media (6.1) | 0.39% | — | Gravity Forms ToolbarAI | 1/10/2024 | 17/6/2026 | The Gravity Forms Toolbar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (5.3) | 0.45% | — | Gravity Forms Multiple Form InstancesAI | 10/7/2024 | 17/6/2026 | The Gravity Forms: Multiple Form Instances plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.1. This is due to the plugin leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application,… | |
| Modificada | Alta (8.8) | 1.5% | — | Xootix Login/signup PopupXootix OTP Login Woocommerce & Gravity FormsXootix Side Cart WoocommerceXootix Waitlist Woocommerce | 6/6/2024 | 17/6/2026 | Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary… | |
| Modificada | Alta (8.8) | 0.22% | — | Brightplugins Block IPS FOR Gravity Forms | 29/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Bright Plugins Block IPs for Gravity Forms.This issue affects Block IPs for Gravity Forms: from n/a through 1.0.1. | |
| Modificada | Crítica (9.8) | 0.62% | — | Gravityforms Gravity Forms | 20/12/2023 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3. | |
| Modificada | Media (6.1) | 0.49% | — | Mediaburst Gravity Forms | 17/7/2023 | 17/6/2026 | The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin. | |
| Modificada | Media (6.5) | 0.31% | — | Gsheetconnector Gravity Forms Google Sheets Connector | 27/6/2023 | 17/6/2026 | The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Modificada | Alta (8.1) | 1.7% | — | Xootix OTP Login Woocommerce & Gravity Forms | 17/5/2023 | 17/6/2026 | The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login via phone number, the plugin returns these codes in an AJAX response. This makes it possible for unauthenticated attackers to… | |
| Modificada | Alta (7.1) | 0.37% | — | WOO Billingo Plus Project WOO Billingo PlusIntegration FOR Billingo & Gravity Forms Project Integration FOR Billingo & Gravity FormsIntegration FOR Szamlazz.hu & Gravity Forms Project Integration FOR Szamlazz.hu & Gravity Forms | 10/10/2022 | 17/6/2026 | The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamlazz.hu & Gravity Forms WordPress plugin before 1.2.7 are lacking CSRF checks in various AJAX actions, which could allow attackers to make logged in Shop Managers and above… | |
| Modificada | Media (6.1) | 3.9% | — | Katz Infusionsoft Gravity Forms | 27/12/2019 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusionsoft Gravity Forms plugin before 1.5.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) go, (2) contactId, or (3) campaignId parameter. | |
| Modificada | Media (6.1) | 0.92% | — | Mediaburst Gravity Forms | 13/8/2019 | 17/6/2026 | The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS. | |
| Modificada | Crítica (9.8) | 4.7% | — | Ajax Upload FOR Gravity Forms Project Ajax Upload FOR Gravity Forms | 8/1/2018 | 17/6/2026 | Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under wp-content/uploads/gravity_forms. | |
| Modificada | Media (6.1) | 0.95% | — | Mediaburst Booking Calendar SMSMediaburst Clockwork SMS NotficationsMediaburst Contact Form 7 SMSMediaburst Fast Secure Contact Form SMS+4 | 20/12/2017 | 17/6/2026 | The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2,… | |
| Modificada | Crítica (9.8) | 41% | — | Aviary Image Editor Add-on FOR Gravity Forms Project Aviary Image Editor Add-on FOR Gravity Forms | 23/5/2017 | 17/6/2026 | Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in… | |
| Modificada | Alta (7.5) | 46% | — | Infusionsoft Gravity Forms Project Infusionsoft Gravity Forms | 26/9/2014 | 17/6/2026 | The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php. |