Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
–

1179 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.49%—Mediaburst Gravity Forms17/7/202317/6/2026
The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.
ModificadaAlta (8.8)0.39%—Gsheetconnector Caldera Forms Google Sheets Connector17/7/202317/6/2026
The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
ModificadaMedia (5.4)0.37%—Basixonline Nex-forms17/7/202317/6/2026
The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only SuperAdmins (in multisite) / admins (in single site) can create forms, however there is a settings allowing them to give lower roles access to such feature.
ModificadaMedia (6.1)0.72%—Gsheetconnector Ninja Forms Google Sheet Connector4/7/202317/6/2026
The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.46%—Gsheetconnector Elementor Forms Google Sheet Connector4/7/202317/6/2026
The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as…
ModificadaMedia (6.1)0.46%—Gsheetconnector Wpforms Google Sheet Connector4/7/202317/6/2026
The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaCrítica (9.1)1.5%—2inc Snow Monkey Forms28/6/202317/6/2026
Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the server.
ModificadaAlta (8.8)22%💥 PoCStrategy11 Formidable Forms27/6/202317/6/2026
The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository…
ModificadaMedia (6.5)0.31%—Gsheetconnector Gravity Forms Google Sheets Connector27/6/202317/6/2026
The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
ModificadaMedia (4.8)0.37%—Fancythemes Optin Forms26/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in FancyThemes Optin Forms – Simple List Building Plugin for WordPress plugin <= 1.3.1 versions.
ModificadaMedia (6.1)0.40%—Wpforms Contact FormWpforms22/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions.
ModificadaMedia (4.8)0.37%—Flothemes FLO Forms20/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Flothemes Flo Forms – Easy Drag & Drop Form Builder plugin <= 1.0.40 versions.
ModificadaAlta (8.8)0.27%—Cformsii Project Cformsii15/6/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions.
ModificadaMedia (4.3)0.30%—Cimatti Contact Forms13/6/202317/6/2026
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms…
ModificadaMedia (4.8)0.44%—Yikesinc Easy Forms FOR Mailchimp12/6/202317/6/2026
The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaBaja (3.7)0.38%—IBM Cics TXIBM Txseries FOR Multiplatforms7/6/202317/6/2026
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques. IBM X-Force ID: 257105.
ModificadaMedia (6.5)0.80%—IBM Cics TXIBM Txseries FOR Multiplatforms7/6/202317/6/2026
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could allow a privileged user to obtain highly sensitive information by enabling debug mode. IBM X-Force ID: 257104.
ModificadaMedia (5.4)0.67%—Flothemes FLO Forms7/6/202317/6/2026
The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Options Change by using the flo_import_forms_options AJAX action in versions up to, and including, 1.0.35 due to insufficient input sanitization and output escaping along with missing capability checks.…
ModificadaAlta (7.1)0.79%—Kaliforms Kali Forms7/6/202317/6/2026
The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the plugin's settings.
ModificadaAlta (8.8)0.48%—Kaliforms Kali Forms7/6/202317/6/2026
The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plugin's function. This makes it possible for unauthenticated attackers to access the plugin's administrative functions via forged request…
ModificadaMedia (5.3)0.73%—Kaliforms Kali Forms7/6/202317/6/2026
The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This makes it possible for unauthenticated attackers to delete any site post…
ModificadaMedia (6.1)0.66%—Wpforms Contact Form7/6/202317/6/2026
The Contact Form & SMTP Plugin by PirateForms plugin for WordPress is vulnerable to HTML injection in the ‘public/class-pirateforms-public.php’ file in versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
ModificadaMedia (4.8)0.60%—Crmperks CRM Perks Forms31/5/202317/6/2026
El plugin CRM Perks Forms para WordPress es vulnerable a Cross-Site Scripting Almacenado a través de la configuración de formularios en versiones hasta la v1.1.1 inclusive debido a la insuficiente sanitización de entrada y escape de salida. Esto hace posible que atacantes autenticados, con permisos de nivel de…
ModificadaMedia (6.1)1.1%💥 ExploitYikesinc Easy Forms FOR Mailchimp30/5/202317/6/2026
The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
ModificadaMedia (6.1)0.38%—Monitorclick Forms ADA29/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MonitorClick Forms Ada – Form Builder plugin <= 1.0 versions.
Orbitaley — Vulnerabilidades