Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.45% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 28/1/2026 | 17/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the CSV export functionality in all versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to download sensitive form submission… | |
| Aplazada | Media (5.3) | 0.28% | — | Crmperks Integration FOR Contact Form 7 HubspotAI | 23/1/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Retrieve Embedded Sensitive Data.This issue affects Integration for Contact Form 7 HubSpot: from n/a through <= 1.4.3. | |
| Aplazada | Media (5.3) | 0.28% | — | Wensolutions Contact Form 7 Getresponse ExtensionAI | 23/1/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WEN Solutions Contact Form 7 GetResponse Extension contact-form-7-getresponse-extension allows Retrieve Embedded Sensitive Data.This issue affects Contact Form 7 GetResponse Extension: from n/a through <= 1.0.8. | |
| Aplazada | Media (6.5) | 0.41% | — | Themehunk Contact Form & Lead Form Elementor BuilderAI | 22/1/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder lead-form-builder allows Retrieve Embedded Sensitive Data.This issue affects Contact Form & Lead Form Elementor Builder: from n/a through <= 2.0.1. | |
| Aplazada | Media (5.3) | 0.61% | — | User Registration Using Contact Form 7AI | 17/1/2026 | 17/6/2026 | The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_cf7_form_data' function in all versions up to, and including, 2.5. This makes it possible for unauthenticated attackers to retrieve form settings which includes… | |
| Aplazada | Media (5.8) | 0.23% | — | Fullworksplugins Quick Contact FormAI | 17/1/2026 | 17/6/2026 | The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6. This is due to the 'qcf_validate_form' AJAX endpoint allowing a user controlled parameter to set the 'from' email address. This makes it possible for unauthenticated attackers to send emails to… | |
| Analizada | Alta (7.4) | 0.22% | — | Codedropz Contact Form 7 | 15/1/2026 | 17/6/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete… | |
| Aplazada | Media (5.3) | 0.35% | — | Contact Form Vcard GeneratorAI | 9/1/2026 | 17/6/2026 | The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_gvccf_check_download_request' function in all versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to export sensitive Contact Form 7… | |
| Aplazada | Media (4.3) | 0.16% | — | Helpdesk Contact FormAI | 7/1/2026 | 17/6/2026 | The HelpDesk contact form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing or incorrect nonce validation on the handle_query_args() function. This makes it possible for unauthenticated attackers to update the plugin's license ID and… | |
| Aplazada | Media (6.1) | 0.37% | — | Drag AND Drop Multiple File Upload Contact Form 7AI | 7/1/2026 | 7/10/2026 | The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files with a dangerous type in all versions up to, and including, 1.3.9.2. This is due to the plugin not blocking .phar and .svg files. This makes it possible for unauthenticated attackers to upload… | |
| Aplazada | Media (5.4) | 0.12% | — | Awplife Contact Form WidgetAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget new-contact-form-widget allows Cross Site Request Forgery.This issue affects Contact Form Widget: from n/a through <= 1.5.1. | |
| Aplazada | Media (4.3) | 0.26% | — | Renzojohnson Contact-form-7-mailchimp-extensionAI | 30/12/2025 | 7/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Renzo Johnson contact-form-7-mailchimp-extension contact-form-7-mailchimp-extension allows Retrieve Embedded Sensitive Data.This issue affects contact-form-7-mailchimp-extension: from n/a through <= 0.9.68. | |
| Aplazada | Alta (7.6) | 0.33% | — | Crmperks Integration FOR Contact Form 7 HubspotAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Blind SQL Injection.This issue affects Integration for Contact Form 7 HubSpot: from n/a through <= 1.4.2. | |
| Aplazada | Alta (8.1) | 0.39% | — | Redirection FOR Contact Form 7AI | 21/12/2025 | 28/9/2026 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_file_to_upload' function in all versions up to, and including, 3.2.7. This makes it possible for unauthenticated attackers to copy arbitrary files on the affected site's… | |
| Aplazada | Alta (8.8) | 0.43% | — | Add-ons.org PDF FOR Contact Form 7AI | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Contact Form 7 pdf-for-contact-form-7 allows Object Injection.This issue affects PDF for Contact Form 7: from n/a through <= 6.5.0. | |
| Aplazada | Media (6.5) | 0.44% | — | Codepeople Contact Form 7 EmailAI | 18/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.60. | |
| Aplazada | Crítica (9.9) | 0.32% | — | Redefiningtheweb Wordpress Contact Form 7 PDF Google Sheet & DatabaseAI | 18/12/2025 | 5/10/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordpress-contact-form-7-pdf allows Using Malicious Files.This issue affects WordPress Contact Form 7 PDF, Google Sheet & Database: from n/a through <= 3.0.0. | |
| Aplazada | Media (4.3) | 0.24% | — | Contact Form 7 Drag AND Drop Template BuilderAI | 12/12/2025 | 17/6/2026 | The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized post duplication due to a missing capability check on the 'rednumber_duplicate' function in all versions up to, and including, 6.3.3. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (4.3) | 0.35% | — | Ultra Addons FOR Contact Form 7AI | 12/12/2025 | 17/6/2026 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'uacf7_get_generated_pdf' function in all versions up to, and including, 3.5.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (4.4) | 0.23% | — | Contact Form 7 With ChatworkAI | 12/12/2025 | 17/6/2026 | The Contact Form 7 with ChatWork plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_token' and 'roomid' settings in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.1) | 0.25% | — | Zealousweb Accept Stripe Payments Using Contact Form 7AI | 12/12/2025 | 30/9/2026 | The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'failure_message' parameter in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (4.3) | 0.13% | — | Fullworksplugins Quick Contact FormAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Quick Contact Form quick-contact-form allows Cross Site Request Forgery.This issue affects Quick Contact Form: from n/a through <= 8.2.5. | |
| Aplazada | Media (5.3) | 0.28% | — | Sevenspark Contact Form 7 Dynamic Text ExtensionAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in sevenspark Contact Form 7 – Dynamic Text Extension contact-form-7-dynamic-text-extension allows Code Injection.This issue affects Contact Form 7 – Dynamic Text Extension: from n/a through <= 5.0.5. | |
| Aplazada | Media (4.3) | 0.28% | — | Bestwebsoft Contact Form PluginAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in bestwebsoft Contact Form by BestWebSoft contact-form-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by BestWebSoft: from n/a through <= 4.3.6. | |
| Aplazada | Media (5.3) | 0.30% | — | Codepeople Booking Calendar Contact FormAI | 22/11/2025 | 17/6/2026 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the `dex_bccf_check_IPN_verification` function. This makes it possible for unauthenticated attackers to… |