Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1179 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.40% | — | Crmperks Contact Form Entries - Contact Form 7 Wpforms AND More | 28/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CRM Perks Contact Form Entries plugin <= 1.3.0 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Chronoengine Chronoforms | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in chronoengine.Com Chronoforms plugin <= 7.0.9 versions. | |
| Modificada | Crítica (9.8) | 2.0% | — | Snow Monkey Forms Project Snow Monkey Forms | 23/5/2023 | 17/6/2026 | Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition. | |
| Modificada | Alta (8.1) | 1.7% | — | Xootix OTP Login Woocommerce & Gravity Forms | 17/5/2023 | 17/6/2026 | The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login via phone number, the plugin returns these codes in an AJAX response. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (6.1) | 0.92% | 💥 Exploit | Ninjaforms Ninja Forms | 15/5/2023 | 17/6/2026 | The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (7.2) | 45% | 💥 PoC | Basixonline Nex-forms | 8/5/2023 | 17/6/2026 | The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query. | |
| Modificada | Media (6.1) | 0.56% | — | Yikesinc Easy Forms FOR Mailchimp | 24/4/2023 | 17/6/2026 | The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Crítica (9.8) | 0.80% | — | Vi-solutions Visforms | 23/4/2023 | 17/6/2026 | The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it. | |
| Modificada | Media (5.4) | 0.38% | — | 1app Business Forms | 23/4/2023 | 17/6/2026 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in 1app Technologies, Inc 1app Business Forms plugin <= 1.0.0 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Reputeinfosystems Arforms Form Builder | 18/4/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versions. | |
| Modificada | Media (5.4) | 0.53% | — | Yikesinc Easy Forms FOR Mailchimp | 17/4/2023 | 17/6/2026 | The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.3) | 0.39% | — | SAP HCM Fiori APP MY Forms | 11/4/2023 | 17/6/2026 | SAP HCM Fiori App My Forms (Fiori 2.0) - version 605, does not perform necessary authorization checks for an authenticated user exposing the restricted header data. | |
| Modificada | Media (5.4) | 0.48% | — | Fluentforms Contact Form | 10/4/2023 | 17/6/2026 | The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in user with roles as low as contributor to inject arbitrary javascript into a form which will trigger for any visitor to the form or admins… | |
| Modificada | Media (6.1) | 0.38% | — | Cimatti Wordpress Contact Forms | 7/4/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Cimatti Wordpress Contact Forms | 7/4/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Quantumcloud Conversational Forms FOR Chatbot | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud Conversational Forms for ChatBot plugin <= 1.1.6 versions. | |
| Modificada | Media (5.4) | 0.50% | — | Basixonline Nex-forms | 27/3/2023 | 17/6/2026 | The NEX-Forms WordPress plugin before 8.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.40% | — | Themekraft Post Form Registration Form Profile Form FOR User Profiles AND Content Forms | 16/3/2023 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions. | |
| Modificada | Media (6.1) | 0.59% | — | A-forms Project A-forms | 10/3/2023 | 16/6/2026 | A vulnerability, which was classified as problematic, was found in MMDeveloper A Forms Plugin up to 1.4.2 on WordPress. This affects an unknown part of the file a-forms.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.4.3 is able to address… | |
| Modificada | Media (6.3) | 0.55% | — | Basixonline Nex-forms | 7/3/2023 | 17/6/2026 | The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including 7.7.1 due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber level permissions and above to invoke these functions… | |
| Modificada | Media (6.1) | 0.42% | — | Frappant Forms Export | 26/2/2023 | 17/6/2026 | The frp_form_answers (aka Forms Export) extension before 3.1.2, and 4.x before 4.0.2, for TYPO3 allows XSS via saved emails. | |
| Modificada | Crítica (9.8) | 0.73% | — | Umbraco Forms | 24/2/2023 | 9/7/2026 | Vulnerabilidad de carga de archivos en Umbraco Forms v.8.7.0 permite a atacantes no autenticados ejecutar código arbitrario a través de un archivo web.config y asp manipulado. | |
| Modificada | Crítica (9.8) | 3.8% | 💥 PoC | Themekraft Buddyforms | 23/2/2023 | 17/6/2026 | The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of… | |
| Modificada | Media (5.4) | 1.6% | — | Zohocorp Zoho Forms | 13/2/2023 | 17/6/2026 | The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.50% | — | Happyforms | 6/2/2023 | 17/6/2026 | The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. |