Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.32%—Gravityforms Gravity FormsAI17/1/202517/6/2026
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…
AplazadaMedia (6.5)0.23%—Wpwebsitecreator WP Website CreatorAIWpformsAIFormidableAINinjaAI+218/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpwebsitecreator Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera wp-website-creator allows Stored XSS.This issue affects Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera:…
AplazadaMedia (6.1)0.39%—Gravity Forms ToolbarAI1/10/202417/6/2026
The Gravity Forms Toolbar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AnalizadaCrítica (9.2)0.56%—Bitdefender Gravityzone31/7/202417/6/2026
A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-5 running only on premise.
AplazadaMedia (5.3)0.45%—Gravity Forms Multiple Form InstancesAI10/7/202417/6/2026
The Gravity Forms: Multiple Form Instances plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.1. This is due to the plugin leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application,…
ModificadaCrítica (9.8)0.43%—Bitdefender Gravityzone6/6/202417/6/2026
A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-2 that are running only on premise.
ModificadaAlta (8.8)1.5%—Xootix Login/signup PopupXootix OTP Login Woocommerce & Gravity FormsXootix Side Cart WoocommerceXootix Waitlist Woocommerce6/6/202417/6/2026
Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary…
AnalizadaCrítica (9.8)0.73%—Bitdefender Endpoint SecurityBitdefender Gravityzone Control Center9/4/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component: Bitdefender…
AnalizadaCrítica (9.8)0.52%—Bitdefender Endpoint SecurityBitdefender Gravityzone Control Center9/4/202417/6/2026
An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint Security for Linux version 7.0.5.200089…
ModificadaMedia (4.8)0.40%—Gravitymaster Product Enquiry FOR Woocommerce22/1/202417/6/2026
The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (4.3)0.20%—Gravitymaster Product Enquiry FOR Woocommerce22/1/202417/6/2026
The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack
AnalizadaMedia (6.1)0.46%—Gravitymaster Product Enquiry FOR Woocommerce16/1/202417/6/2026
The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaAlta (8.8)0.22%—Brightplugins Block IPS FOR Gravity Forms29/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Bright Plugins Block IPs for Gravity Forms.This issue affects Block IPs for Gravity Forms: from n/a through 1.0.1.
ModificadaCrítica (9.8)0.62%—Gravityforms Gravity Forms20/12/202317/6/2026
Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.
ModificadaAlta (8.8)0.27%—Gravitymaster Product Enquiry FOR Woocommerce18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Gravity Master Product Enquiry for WooCommerce.This issue affects Product Enquiry for WooCommerce: from n/a through 3.0.
AnalizadaMedia (6.1)0.41%—Gravitymaster Product Enquiry FOR Woocommerce16/11/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions.
ModificadaMedia (6.1)0.43%—Gravitymaster Product Enquiry FOR Woocommerce13/11/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions.
ModificadaMedia (5.4)0.54%—Gravitydesign Telephone Number Linker7/11/202317/6/2026
The Telephone Number Linker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'telnumlink' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaMedia (6.1)0.49%—Mediaburst Gravity Forms17/7/202317/6/2026
The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.
ModificadaMedia (6.5)0.31%—Gsheetconnector Gravity Forms Google Sheets Connector27/6/202317/6/2026
The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
ModificadaAlta (8.1)1.7%—Xootix OTP Login Woocommerce & Gravity Forms17/5/202317/6/2026
The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login via phone number, the plugin returns these codes in an AJAX response. This makes it possible for unauthenticated attackers to…
ModificadaAlta (7.1)0.37%—WOO Billingo Plus Project WOO Billingo PlusIntegration FOR Billingo & Gravity Forms Project Integration FOR Billingo & Gravity FormsIntegration FOR Szamlazz.hu & Gravity Forms Project Integration FOR Szamlazz.hu & Gravity Forms10/10/202217/6/2026
The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamlazz.hu & Gravity Forms WordPress plugin before 1.2.7 are lacking CSRF checks in various AJAX actions, which could allow attackers to make logged in Shop Managers and above…
ModificadaCrítica (9.8)0.92%—Bitdefender Gravityzone5/9/202217/6/2026
Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass unsafe commands to the environment. This issue affects: Bitdefender GravityZone Console On-Premise versions prior to 6.29.2-1. Bitdefender GravityZone Cloud Console versions…
ModificadaAlta (7.5)1.2%—Bitdefender Endpoint Security ToolsBitdefender GravityzoneBitdefender Update Server7/4/202217/6/2026
Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint Security Tools (in relay role), GravityZone (in Update Server role) allows an attacker to cause a Denial-of-Service. This issue affects: Bitdefender Update Server versions prior to 3.4.0.276.…
ModificadaAlta (7.8)0.31%—Bitdefender Gravityzone16/12/202117/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects Bitdefender GravityZone versions prior to 3.3.8.272