Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1179 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.40%—Crmperks Contact Form Entries - Contact Form 7 Wpforms AND More28/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CRM Perks Contact Form Entries plugin <= 1.3.0 versions.
ModificadaAlta (8.8)0.26%—Chronoengine Chronoforms25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in chronoengine.Com Chronoforms plugin <= 7.0.9 versions.
ModificadaCrítica (9.8)2.0%—Snow Monkey Forms Project Snow Monkey Forms23/5/202317/6/2026
Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition.
ModificadaAlta (8.1)1.7%—Xootix OTP Login Woocommerce & Gravity Forms17/5/202317/6/2026
The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login via phone number, the plugin returns these codes in an AJAX response. This makes it possible for unauthenticated attackers to…
ModificadaMedia (6.1)0.92%💥 ExploitNinjaforms Ninja Forms15/5/202317/6/2026
The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaAlta (7.2)45%💥 PoCBasixonline Nex-forms8/5/202317/6/2026
The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query.
ModificadaMedia (6.1)0.56%—Yikesinc Easy Forms FOR Mailchimp24/4/202317/6/2026
The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaCrítica (9.8)0.80%—Vi-solutions Visforms23/4/202317/6/2026
The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it.
ModificadaMedia (5.4)0.38%—1app Business Forms23/4/202317/6/2026
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in 1app Technologies, Inc 1app Business Forms plugin <= 1.0.0 versions.
ModificadaMedia (6.1)0.41%—Reputeinfosystems Arforms Form Builder18/4/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versions.
ModificadaMedia (5.4)0.53%—Yikesinc Easy Forms FOR Mailchimp17/4/202317/6/2026
The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (4.3)0.39%—SAP HCM Fiori APP MY Forms11/4/202317/6/2026
SAP HCM Fiori App My Forms (Fiori 2.0) - version 605, does not perform necessary authorization checks for an authenticated user exposing the restricted header data.
ModificadaMedia (5.4)0.48%—Fluentforms Contact Form10/4/202317/6/2026
The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in user with roles as low as contributor to inject arbitrary javascript into a form which will trigger for any visitor to the form or admins…
ModificadaMedia (6.1)0.38%—Cimatti Wordpress Contact Forms7/4/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.
ModificadaMedia (6.1)0.38%—Cimatti Wordpress Contact Forms7/4/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.
ModificadaMedia (4.8)0.39%—Quantumcloud Conversational Forms FOR Chatbot6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud Conversational Forms for ChatBot plugin <= 1.1.6 versions.
ModificadaMedia (5.4)0.50%—Basixonline Nex-forms27/3/202317/6/2026
The NEX-Forms WordPress plugin before 8.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (5.4)0.40%—Themekraft Post Form Registration Form Profile Form FOR User Profiles AND Content Forms16/3/202317/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.
ModificadaMedia (6.1)0.59%—A-forms Project A-forms10/3/202316/6/2026
A vulnerability, which was classified as problematic, was found in MMDeveloper A Forms Plugin up to 1.4.2 on WordPress. This affects an unknown part of the file a-forms.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.4.3 is able to address…
ModificadaMedia (6.3)0.55%—Basixonline Nex-forms7/3/202317/6/2026
The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including 7.7.1 due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber level permissions and above to invoke these functions…
ModificadaMedia (6.1)0.42%—Frappant Forms Export26/2/202317/6/2026
The frp_form_answers (aka Forms Export) extension before 3.1.2, and 4.x before 4.0.2, for TYPO3 allows XSS via saved emails.
ModificadaCrítica (9.8)0.73%—Umbraco Forms24/2/20239/7/2026
Vulnerabilidad de carga de archivos en Umbraco Forms v.8.7.0 permite a atacantes no autenticados ejecutar código arbitrario a través de un archivo web.config y asp manipulado.
ModificadaCrítica (9.8)3.8%💥 PoCThemekraft Buddyforms23/2/202317/6/2026
The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of…
ModificadaMedia (5.4)1.6%—Zohocorp Zoho Forms13/2/202317/6/2026
The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.50%—Happyforms6/2/202317/6/2026
The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Orbitaley — Vulnerabilidades