Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.25%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 724/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.
ModificadaMedia (6.1)0.54%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 717/4/202317/6/2026
The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a…
ModificadaCrítica (9.8)3.0%💥 PoCCodedropz Drag AND Drop Multiple File Upload - Contact Form 71/3/202317/6/2026
A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack…
ModificadaMedia (4.3)0.59%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 717/10/202217/6/2026
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.
ModificadaCrítica (9.8)1.4%—Creativedream File Uploader Project Creativedream File Uploader3/10/202217/6/2026
Arbitrary file upload vulnerability in php uploader
ModificadaMedia (5.4)14%💥 ExploitCodedropz Drag AND Drop Multiple File Upload - Contact Form 728/3/202217/6/2026
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue
ModificadaAlta (8.8)2.8%—Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO28/3/202217/6/2026
The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code…
ModificadaMedia (6.1)0.78%—Ninjaforms Ninja Forms File Uploads23/3/202217/6/2026
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add malicious web scripts to vulnerable…
ModificadaCrítica (9.8)39%—Ninjaforms Ninja Forms File Uploads23/3/202217/6/2026
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to…
ModificadaMedia (5.4)0.67%—Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO7/3/202217/6/2026
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
ModificadaMedia (5.4)0.67%—Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO7/3/202217/6/2026
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks
ModificadaMedia (6.1)0.89%—Johndatserakis File-upload-with-preview5/9/202117/6/2026
This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file).
ModificadaCrítica (9.8)79%💥 ExploitCodedropz Drag AND Drop Multiple File Upload - Contact Form 78/6/202017/6/2026
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
ModificadaCrítica (9.8)8.6%—Iptanus Wordpress File Upload13/3/202017/6/2026
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.
ModificadaCrítica (9.8)92%💥 ExploitCreative-solutions Creative Contact FormJquery File Upload Project Jquery File Upload8/2/202017/6/2026
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by…
ModificadaAlta (7.5)1.4%—Iptanus Wordpress File Upload22/8/201917/6/2026
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
ModificadaAlta (7.5)1.4%—Iptanus Wordpress File Upload22/8/201917/6/2026
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
ModificadaAlta (7.5)1.4%—Iptanus Wordpress File Upload22/8/201917/6/2026
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
ModificadaAlta (7.5)1.4%—Iptanus Wordpress File Upload22/8/201917/6/2026
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
ModificadaAlta (8.1)8.0%💥 PoCNinjaforms Ninja Forms File Uploads7/5/201917/8/2026
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.
ModificadaCrítica (9.8)97%💥 ExploitJquery File Upload Project Jquery File Upload11/10/201812/8/2026
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
ModificadaMedia (6.1)3.6%💥 ExploitIptanus Wordpress File Upload7/4/201817/6/2026
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
ModificadaMedia (5.4)3.1%💥 ExploitIptanus Wordpress File Upload1/4/201817/6/2026
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
ModificadaMedia (6.8)0.73%—Webform Multiple File Upload Project Webform Multiple File Upload15/6/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the Webform Multiple File Upload module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of certain users for requests that delete files via unspecified vectors.
ModificadaMedia (6.5)1.7%—Najeebmedia N-media File Uploader26/9/201417/6/2026
Unrestricted file upload vulnerability in the N-Media file uploader plugin before 3.4 for WordPress allows remote authenticated users to execute arbitrary PHP code by leveraging Author privileges to store a file.
Orbitaley — Vulnerabilidades