Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.21% | — | Nitinrathod WP Forms Puzzle Captcha | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Stored XSS.This issue affects WP Forms Puzzle Captcha: from n/a through 4.1. | |
| Modificada | Alta (8.8) | 0.30% | — | Vsourz CF7 Invisible Recaptcha | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Vsourz Digital CF7 Invisible reCAPTCHA plugin <= 1.3.3 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Featherplugins Custom Login Page | Temporary Users | Rebrand Login | Login Captcha | 6/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha plugin <= 1.1.3 versions. | |
| Modificada | Media (4.8) | 0.32% | — | Webcource WC Captcha | 31/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebCource WC Captcha plugin <= 1.4 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Nitinrathod WP Forms Puzzle Captcha | 11/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nitin Rathod WP Forms Puzzle Captcha plugin <= 4.1 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Devnath Verma WP Captcha | 9/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Devnath verma WP Captcha plugin <= 2.0.0 versions. | |
| Modificada | Media (5.3) | 0.67% | — | Hcaptcha FOR Ext\ Form Project | 23/8/2023 | 17/6/2026 | An issue was discovered in the hcaptcha (aka hCaptcha for EXT:form) extension before 2.1.2 for TYPO3. It fails to check that the required captcha field is submitted in the form data. allowing a remote user to bypass the CAPTCHA check. | |
| Modificada | Media (4.8) | 0.37% | — | Fuzzguard Captcha Them ALL | 16/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Benjamin Guy Captcha Them All plugin <= 1.3.3 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Easy Captcha Project Easy Captcha | 18/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wppal Easy Captcha plugin <= 1.0 versions. | |
| Modificada | Media (5.4) | 0.61% | — | Flexible Captcha Project Flexible Captcha | 6/2/2023 | 17/6/2026 | The Flexible Captcha WordPress plugin through 4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.75% | — | Cool-php-captcha Project Cool-php-captcha | 13/1/2023 | 16/6/2026 | A vulnerability classified as problematic was found in jianlinwei cool-php-captcha up to 0.2. This vulnerability affects unknown code of the file example-form.php. The manipulation of the argument captcha with the input %3Cscript%3Ealert(1)%3C/script%3E leads to cross site scripting. The attack can be initiated… | |
| Modificada | Media (4.8) | 0.56% | — | Recaptcha Project Recaptcha | 28/11/2022 | 17/6/2026 | The reCAPTCHA WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.3) | 0.76% | — | Login NO Captcha Recaptcha Project Login NO Captcha Recaptcha | 16/9/2022 | 17/6/2026 | The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen. | |
| Modificada | Alta (8.8) | 0.36% | — | Captcha Code Project Captcha Code | 9/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza's Captcha Code plugin <= 2.7 at WordPress. | |
| Modificada | Alta (8.8) | 0.60% | — | Wpwhitesecurity Captcha 4WP | 1/8/2022 | 17/6/2026 | The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abused by attackers, via a Cross-Site Request Forgery attack to run arbitrary code on the server. | |
| Modificada | Crítica (9.8) | 1.6% | — | Scu-captcha Project Scu-captcha | 22/7/2022 | 17/6/2026 | The scu-captcha package in PyPI v0.0.1 to v0.0.4 included a code execution backdoor inserted by a third party. | |
| Modificada | Media (6.1) | 1.5% | 💥 Exploit | Contact Form 7 Captcha Project Contact Form 7 Captcha | 17/7/2022 | 17/6/2026 | The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers | |
| Modificada | Media (5.3) | 1.2% | — | Flask-session-captcha Project Flask-session-captcha | 25/4/2022 | 17/6/2026 | flask-session-captcha is a package which allows users to extend Flask by adding an image based captcha stored in a server side session. In versions prior to 1.2.1, he `captcha.validate()` function would return `None` if passed no value (e.g. by submitting an having an empty form). If implementing users were checking… | |
| Modificada | Alta (8.8) | 0.63% | — | Contact Form With Captcha Project Contact Form With Captcha | 29/11/2021 | 17/6/2026 | The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php file during contact form submission, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.6.2. | |
| Modificada | Alta (8.8) | 0.72% | — | Contact Form 7 Captcha Project Contact Form 7 Captcha | 23/8/2021 | 17/6/2026 | The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored Cross-Site Scripting issue. | |
| Modificada | Media (6.1) | 0.58% | — | Recaptcha Solver Project Recaptcha Solver | 22/8/2021 | 17/6/2026 | An XSS issue was discovered in ReCaptcha Solver 5.7. A response from Anti-Captcha.com, RuCaptcha.com, 2captcha.com, DEATHbyCAPTCHA.com, ImageTyperz.com, or BestCaptchaSolver.com in setCaptchaCode() is inserted into the DOM as HTML, resulting in full control over the user's browser by these servers. | |
| Modificada | Media (5.4) | 0.56% | — | JH Captcha Project JH Captcha | 7/7/2020 | 17/6/2026 | The jh_captcha extension through 2.1.3, and 3.x through 3.0.2, for TYPO3 allows XSS. | |
| Modificada | Media (6.1) | 0.92% | — | Vsourz CF7 Invisible Recaptcha | 9/9/2019 | 17/6/2026 | The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS. | |
| Modificada | Crítica (9.8) | 3.1% | — | Simple Captcha2 Project Simple Captcha2 | 26/7/2019 | 17/6/2026 | The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. | |
| Modificada | Crítica (9.8) | 2.5% | — | PS Phpcaptcha WP Project PS Phpcaptcha WP | 5/2/2019 | 17/6/2026 | The PS PHPCaptcha WP plugin before v1.2.0 for WordPress mishandles sanitization of input values. |