Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

115 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.21%—Nitinrathod WP Forms Puzzle Captcha30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Stored XSS.This issue affects WP Forms Puzzle Captcha: from n/a through 4.1.
ModificadaAlta (8.8)0.30%—Vsourz CF7 Invisible Recaptcha12/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Vsourz Digital CF7 Invisible reCAPTCHA plugin <= 1.3.3 versions.
ModificadaAlta (8.8)0.21%—Featherplugins Custom Login Page | Temporary Users | Rebrand Login | Login Captcha6/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha plugin <= 1.1.3 versions.
ModificadaMedia (4.8)0.32%—Webcource WC Captcha31/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebCource WC Captcha plugin <= 1.4 versions.
ModificadaAlta (8.8)0.21%—Nitinrathod WP Forms Puzzle Captcha11/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nitin Rathod WP Forms Puzzle Captcha plugin <= 4.1 versions.
ModificadaAlta (8.8)0.26%—Devnath Verma WP Captcha9/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Devnath verma WP Captcha plugin <= 2.0.0 versions.
ModificadaMedia (5.3)0.67%—Hcaptcha FOR Ext\ Form Project23/8/202317/6/2026
An issue was discovered in the hcaptcha (aka hCaptcha for EXT:form) extension before 2.1.2 for TYPO3. It fails to check that the required captcha field is submitted in the form data. allowing a remote user to bypass the CAPTCHA check.
ModificadaMedia (4.8)0.37%—Fuzzguard Captcha Them ALL16/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Benjamin Guy Captcha Them All plugin <= 1.3.3 versions.
ModificadaMedia (6.1)0.38%—Easy Captcha Project Easy Captcha18/7/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wppal Easy Captcha plugin <= 1.0 versions.
ModificadaMedia (5.4)0.61%—Flexible Captcha Project Flexible Captcha6/2/202317/6/2026
The Flexible Captcha WordPress plugin through 4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.1)0.75%—Cool-php-captcha Project Cool-php-captcha13/1/202316/6/2026
A vulnerability classified as problematic was found in jianlinwei cool-php-captcha up to 0.2. This vulnerability affects unknown code of the file example-form.php. The manipulation of the argument captcha with the input %3Cscript%3Ealert(1)%3C/script%3E leads to cross site scripting. The attack can be initiated…
ModificadaMedia (4.8)0.56%—Recaptcha Project Recaptcha28/11/202217/6/2026
The reCAPTCHA WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (4.3)0.76%—Login NO Captcha Recaptcha Project Login NO Captcha Recaptcha16/9/202217/6/2026
The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.
ModificadaAlta (8.8)0.36%—Captcha Code Project Captcha Code9/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza's Captcha Code plugin <= 2.7 at WordPress.
ModificadaAlta (8.8)0.60%—Wpwhitesecurity Captcha 4WP1/8/202217/6/2026
The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abused by attackers, via a Cross-Site Request Forgery attack to run arbitrary code on the server.
ModificadaCrítica (9.8)1.6%—Scu-captcha Project Scu-captcha22/7/202217/6/2026
The scu-captcha package in PyPI v0.0.1 to v0.0.4 included a code execution backdoor inserted by a third party.
ModificadaMedia (6.1)1.5%💥 ExploitContact Form 7 Captcha Project Contact Form 7 Captcha17/7/202217/6/2026
The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
ModificadaMedia (5.3)1.2%—Flask-session-captcha Project Flask-session-captcha25/4/202217/6/2026
flask-session-captcha is a package which allows users to extend Flask by adding an image based captcha stored in a server side session. In versions prior to 1.2.1, he `captcha.validate()` function would return `None` if passed no value (e.g. by submitting an having an empty form). If implementing users were checking…
ModificadaAlta (8.8)0.63%—Contact Form With Captcha Project Contact Form With Captcha29/11/202117/6/2026
The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php file during contact form submission, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.6.2.
ModificadaAlta (8.8)0.72%—Contact Form 7 Captcha Project Contact Form 7 Captcha23/8/202117/6/2026
The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored Cross-Site Scripting issue.
ModificadaMedia (6.1)0.58%—Recaptcha Solver Project Recaptcha Solver22/8/202117/6/2026
An XSS issue was discovered in ReCaptcha Solver 5.7. A response from Anti-Captcha.com, RuCaptcha.com, 2captcha.com, DEATHbyCAPTCHA.com, ImageTyperz.com, or BestCaptchaSolver.com in setCaptchaCode() is inserted into the DOM as HTML, resulting in full control over the user's browser by these servers.
ModificadaMedia (5.4)0.56%—JH Captcha Project JH Captcha7/7/202017/6/2026
The jh_captcha extension through 2.1.3, and 3.x through 3.0.2, for TYPO3 allows XSS.
ModificadaMedia (6.1)0.92%—Vsourz CF7 Invisible Recaptcha9/9/201917/6/2026
The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS.
ModificadaCrítica (9.8)3.1%—Simple Captcha2 Project Simple Captcha226/7/201917/6/2026
The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.
ModificadaCrítica (9.8)2.5%—PS Phpcaptcha WP Project PS Phpcaptcha WP5/2/201917/6/2026
The PS PHPCaptcha WP plugin before v1.2.0 for WordPress mishandles sanitization of input values.
Orbitaley — Vulnerabilidades