Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
1179 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.49% | — | Mediaburst Gravity Forms | 17/7/2023 | 17/6/2026 | The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin. | |
| Modificada | Alta (8.8) | 0.39% | — | Gsheetconnector Caldera Forms Google Sheets Connector | 17/7/2023 | 17/6/2026 | The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Modificada | Media (5.4) | 0.37% | — | Basixonline Nex-forms | 17/7/2023 | 17/6/2026 | The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only SuperAdmins (in multisite) / admins (in single site) can create forms, however there is a settings allowing them to give lower roles access to such feature. | |
| Modificada | Media (6.1) | 0.72% | — | Gsheetconnector Ninja Forms Google Sheet Connector | 4/7/2023 | 17/6/2026 | The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.1) | 0.46% | — | Gsheetconnector Elementor Forms Google Sheet Connector | 4/7/2023 | 17/6/2026 | The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as… | |
| Modificada | Media (6.1) | 0.46% | — | Gsheetconnector Wpforms Google Sheet Connector | 4/7/2023 | 17/6/2026 | The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Crítica (9.1) | 1.5% | — | 2inc Snow Monkey Forms | 28/6/2023 | 17/6/2026 | Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the server. | |
| Modificada | Alta (8.8) | 22% | 💥 PoC | Strategy11 Formidable Forms | 27/6/2023 | 17/6/2026 | The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository… | |
| Modificada | Media (6.5) | 0.31% | — | Gsheetconnector Gravity Forms Google Sheets Connector | 27/6/2023 | 17/6/2026 | The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Modificada | Media (4.8) | 0.37% | — | Fancythemes Optin Forms | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in FancyThemes Optin Forms – Simple List Building Plugin for WordPress plugin <= 1.3.1 versions. | |
| Modificada | Media (6.1) | 0.40% | — | Wpforms Contact FormWpforms | 22/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Flothemes FLO Forms | 20/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Flothemes Flo Forms – Easy Drag & Drop Form Builder plugin <= 1.0.40 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | Cformsii Project Cformsii | 15/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions. | |
| Modificada | Media (4.3) | 0.30% | — | Cimatti Contact Forms | 13/6/2023 | 17/6/2026 | The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms… | |
| Modificada | Media (4.8) | 0.44% | — | Yikesinc Easy Forms FOR Mailchimp | 12/6/2023 | 17/6/2026 | The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Baja (3.7) | 0.38% | — | IBM Cics TXIBM Txseries FOR Multiplatforms | 7/6/2023 | 17/6/2026 | IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques. IBM X-Force ID: 257105. | |
| Modificada | Media (6.5) | 0.80% | — | IBM Cics TXIBM Txseries FOR Multiplatforms | 7/6/2023 | 17/6/2026 | IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could allow a privileged user to obtain highly sensitive information by enabling debug mode. IBM X-Force ID: 257104. | |
| Modificada | Media (5.4) | 0.67% | — | Flothemes FLO Forms | 7/6/2023 | 17/6/2026 | The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Options Change by using the flo_import_forms_options AJAX action in versions up to, and including, 1.0.35 due to insufficient input sanitization and output escaping along with missing capability checks.… | |
| Modificada | Alta (7.1) | 0.79% | — | Kaliforms Kali Forms | 7/6/2023 | 17/6/2026 | The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the plugin's settings. | |
| Modificada | Alta (8.8) | 0.48% | — | Kaliforms Kali Forms | 7/6/2023 | 17/6/2026 | The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plugin's function. This makes it possible for unauthenticated attackers to access the plugin's administrative functions via forged request… | |
| Modificada | Media (5.3) | 0.73% | — | Kaliforms Kali Forms | 7/6/2023 | 17/6/2026 | The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This makes it possible for unauthenticated attackers to delete any site post… | |
| Modificada | Media (6.1) | 0.66% | — | Wpforms Contact Form | 7/6/2023 | 17/6/2026 | The Contact Form & SMTP Plugin by PirateForms plugin for WordPress is vulnerable to HTML injection in the ‘public/class-pirateforms-public.php’ file in versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Media (4.8) | 0.60% | — | Crmperks CRM Perks Forms | 31/5/2023 | 17/6/2026 | El plugin CRM Perks Forms para WordPress es vulnerable a Cross-Site Scripting Almacenado a través de la configuración de formularios en versiones hasta la v1.1.1 inclusive debido a la insuficiente sanitización de entrada y escape de salida. Esto hace posible que atacantes autenticados, con permisos de nivel de… | |
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | Yikesinc Easy Forms FOR Mailchimp | 30/5/2023 | 17/6/2026 | The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Media (6.1) | 0.38% | — | Monitorclick Forms ADA | 29/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MonitorClick Forms Ada – Form Builder plugin <= 1.0 versions. |