Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
313 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.19% | — | Brainstormforce SureformsAI | 20/9/2025 | 17/6/2026 | The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.36% | — | Brainstormforce SuredashAI | 20/8/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Brainstorm Force SureDash suredash allows Privilege Escalation.This issue affects SureDash: from n/a through <= 1.0.3. | |
| Aplazada | Media (6.5) | 0.35% | — | Brainstormforce SuredashAI | 14/8/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Brainstorm Force SureDash suredash allows Retrieve Embedded Sensitive Data.This issue affects SureDash: from n/a through <= 1.1.0. | |
| Aplazada | Media (4.3) | 0.25% | — | Brainstormforce Ultimate Addons FOR ElementorAI | 2/8/2025 | 17/6/2026 | The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, 2.4.6. This makes it possible for… | |
| Analizada | Media (5.8) | 0.18% | — | Brainstormforce Sureforms | 1/8/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users. | |
| Analizada | Alta (7.5) | 0.55% | — | Brainstormforce Sureforms | 9/7/2025 | 17/6/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.3 via the use of file_exists() in the delete_entry_files() function without restriction on the path provided. This makes it possible for unauthenticated… | |
| Analizada | Alta (8.1) | 1.0% | — | Brainstormforce Sureforms | 9/7/2025 | 17/6/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to delete arbitrary… | |
| Analizada | Baja (3.5) | 0.27% | — | Brainstormforce Sureforms | 2/5/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Baja (3.5) | 0.31% | — | Brainstormforce Sureforms | 2/5/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Crítica (9.8) | 54% | 💥 Exploit | Brainstormforce OttokitAIBrainstormforce SuretriggersAI | 1/5/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82. | |
| Analizada | Media (4.9) | 0.35% | — | Brainstormforce Sureforms | 30/4/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action | |
| Aplazada | Media (6.5) | 0.22% | — | Stormhillmedia MybookprogressAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookProgress by Stormhill Media mybookprogress allows Stored XSS.This issue affects MyBookProgress by Stormhill Media: from n/a through <= 1.0.8. | |
| Aplazada | Alta (7.1) | 0.29% | — | Tribulant Software Snow StormAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Snow Storm snow-storm allows Reflected XSS.This issue affects Snow Storm: from n/a through <= 1.4.6. | |
| Aplazada | Alta (7.3) | 0.30% | — | Stormshield Network SecurityAI | 1/4/2025 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on different interfaces, it may be possible to interrupt multicast traffic on some of these interfaces. That could result in a denial of the multicast routing service on the firewall. | |
| Aplazada | Media (4.3) | 0.25% | — | Stormhillmedia MybookprogressAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in zookatron MyBookProgress by Stormhill Media mybookprogress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MyBookProgress by Stormhill Media: from n/a through <= 1.0.8. | |
| Aplazada | Media (4.3) | 0.21% | — | Brainstormforce Astra-sitesAI | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates astra-sites allows Cross Site Request Forgery.This issue affects Starter Templates: from n/a through <= 4.4.9. | |
| Aplazada | Media (6.4) | 0.34% | — | Stormhillmedia MybookprogressAI | 17/1/2025 | 17/6/2026 | The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘book’ parameter in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Analizada | Media (5.3) | 0.34% | — | Brainstormforce Sureforms | 8/1/2025 | 17/6/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated attackers to export data from password… | |
| Modificada | Media (5.4) | 0.30% | — | Brainstormforce Astra Widgets | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets astra-widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through <= 1.2.15. | |
| Analizada | Media (5.4) | 0.31% | — | Brainstormforce Elementor Header & Footer Builder | 23/12/2024 | 17/6/2026 | The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ parameter in all versions up to, and including, 1.6.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Modificada | Crítica (9.8) | 0.65% | — | Brainstormforce Spectra | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0. | |
| Modificada | Alta (8.8) | 0.55% | — | Brainstormforce Spectra | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0. | |
| Analizada | Media (5.4) | 0.30% | — | Brainstormforce Spectra | 3/12/2024 | 17/6/2026 | The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, and including, 2.16.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.8) | 0.23% | — | Skipstorm SK WP Settings BackupAI | 16/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object Injection.This issue affects SK WP Settings Backup: from n/a through <= 1.0. | |
| Analizada | Alta (7.8) | 0.11% | — | Jetbrains Webstorm | 15/11/2024 | 17/6/2026 | In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script |