Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
1178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.49% | — | Custom Contact FormsAI | 5/9/2026 | 8/9/2026 | The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above,… | |
| Aplazada | Alta (7.2) | 0.25% | — | Ninjaforms Ninja FormsAI | 5/9/2026 | 8/9/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Alta (7.2) | 0.29% | — | Brainstormforce SureformsAI | 5/9/2026 | 8/9/2026 | The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.19% | — | Gravityforms Gravity FormsAI | 5/9/2026 | 8/9/2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Media (5.9) | 0.23% | — | Thedotstore Ninja FormsAI | 4/9/2026 | 8/9/2026 | The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2… | |
| Aplazada | Media (5.3) | 0.34% | — | Brainstormforce SureformsAI | 3/9/2026 | 7/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5. | |
| Aplazada | Alta (7.1) | 0.25% | — | Ninjaforms File Uploads ExtensionAI | 3/9/2026 | 5/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| Aplazada | Media (6.5) | 0.36% | — | Hipaa FormsAI | 2/9/2026 | 3/9/2026 | The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints. | |
| Aplazada | Alta (8.8) | 0.46% | — | Ninjaforms Ninja Forms - Layout & StylesAI | 2/9/2026 | 3/9/2026 | Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. | |
| Aplazada | Crítica (9.8) | 1.0% | — | Sigmaforms PROAI | 2/9/2026 | 2/9/2026 | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the… | |
| Aplazada | Alta (8.1) | 0.50% | — | Gravityforms Gravity FormsAI | 1/9/2026 | 1/9/2026 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in the `GFAsyncUpload::upload()` function, where public form state URL hashes can be reused as chunk continuation hashes and… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Smart Marketing SMS AND Newsletters FormsAI | 31/8/2026 | 2/9/2026 | Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Fluentforms Fluent Forms PROAI | 31/8/2026 | 1/9/2026 | Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 31/8/2026 | 1/9/2026 | Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | |
| Aplazada | Crítica (9.8) | 0.69% | — | Sigma Forms PROAI | 29/8/2026 | 31/8/2026 | The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to all users during form submissions and bypassing MIME type validation… | |
| Aplazada | Media (4.3) | 0.25% | — | WP Full PAY Stripe Payment FormsAI | 29/8/2026 | 31/8/2026 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it, allowing a user with a confirmed portal session to cancel subscriptions belonging to other customers. Exploitation… | |
| Aplazada | Media (5.3) | 0.41% | — | Wpeverest Everest FormsAI | 28/8/2026 | 28/8/2026 | The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload fields without domain restriction, which are… | |
| Aplazada | Alta (8.8) | 0.73% | — | Silverstripe UserformsAISilverstripe CMSAI | 27/8/2026 | 9/9/2026 | Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authenticated CMS user with permission to… | |
| Aplazada | Media (5.3) | 0.29% | — | Kaliforms Kali FormsAI | 27/8/2026 | 28/8/2026 | Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions. | |
| Aplazada | Alta (7.5) | 0.69% | — | Formidable ChartsAIFormidable FormsAI | 26/8/2026 | 27/8/2026 | The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Successful… | |
| Aplazada | Alta (7.2) | 0.41% | — | Strategy11 Formidable FormsAI | 26/8/2026 | 26/8/2026 | The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frm_user_id' parameter in all versions up to, and including, 6.33.1 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (4.3) | 0.25% | — | WP Full PAY Stripe Payment FormsAI | 26/8/2026 | 26/8/2026 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal session to cancel, reactivate or modify subscriptions belonging to other… | |
| Aplazada | Media (5.3) | 0.34% | — | WP Full PAY Stripe Payment FormsAI | 26/8/2026 | 26/8/2026 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal session has completed its confirmation step before returning data, allowing unauthenticated users to read another customer's subscription and billing information. | |
| Aplazada | Media (6.1) | 0.28% | — | Nopaperforms Niaa-chatbotAI | 24/8/2026 | 9/9/2026 | A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter. | |
| Aplazada | Alta (7.5) | 0.50% | — | Super-forms Super FormsAI | 24/8/2026 | 24/8/2026 | Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions. |