Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
125 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.26% | — | Strategy11 Formidable Form Builder | 28/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Form Builder Team Formidable Forms plugin <= 5.5.6 versions. | |
| Modificada | Media (6.1) | 0.62% | — | Php-form-builder-class Project Php-form-builder-class | 12/1/2023 | 16/6/2026 | A vulnerability has been found in manikandan170890 php-form-builder-class and classified as problematic. Affected by this vulnerability is an unknown functionality of the file PFBC/Element/Textarea.php of the component Textarea Handler. The manipulation of the argument value leads to cross site scripting. The attack… | |
| Modificada | Media (4.8) | 0.40% | — | Whitestudio Easy Form Builder | 12/12/2022 | 17/6/2026 | The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.8) | 0.63% | — | Codepeople Form Builder CP | 19/9/2022 | 17/6/2026 | The Form Builder CP WordPress plugin before 1.2.32 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.5) | 8.8% | 💥 Exploit | Wpmet Metform Elementor Contact Form Builder | 10/5/2022 | 17/6/2026 | The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot,… | |
| Modificada | Media (4.8) | 0.60% | — | Vfbpro Visual Form Builder | 2/5/2022 | 17/6/2026 | The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Crítica (9.8) | 2.9% | — | Vfbpro Visual Form Builder | 12/4/2022 | 17/6/2026 | The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | |
| Modificada | Alta (8.1) | 0.47% | — | Vfbpro Visual Form Builder | 12/4/2022 | 17/6/2026 | The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks | |
| Modificada | Media (5.3) | 3.8% | 💥 Exploit | Vfbpro Visual Form Builder | 12/4/2022 | 17/6/2026 | The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint. | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (4.8) | 0.62% | — | Reputeinfosystems Contact Form, Survey & Popup Form Plugin FOR Wordpress - Arforms Form Builder | 6/12/2021 | 17/6/2026 | The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Crítica (9.6) | 3.1% | 💥 PoC | Strategy11 Formidable Form Builder | 25/10/2021 | 17/6/2026 | The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link. If… | |
| Modificada | Media (4.8) | 0.68% | — | Strategy11 Formidable Form Builder | 25/10/2021 | 17/6/2026 | The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (4.8) | 0.62% | — | Vfbpro Visual Form Builder | 25/10/2021 | 17/6/2026 | The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed | |
| Modificada | Media (5.4) | 0.62% | — | Web-settler Form Builder | 6/9/2021 | 17/6/2026 | The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed | |
| Modificada | Alta (8.8) | 1.9% | — | Easy-form-builder-by-bitware Project Easy-form-builder-by-bitware | 12/4/2021 | 17/6/2026 | The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticated users, does not have any security in place to verify uploaded files, allowing low privilege users to upload arbitrary files, leading to RCE. | |
| Modificada | Media (4.8) | 1.4% | — | Form Builder FOR Magento 2 Project Form Builder FOR Magento 2 | 29/6/2020 | 17/6/2026 | Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Current_url or email field, or the User-Agent HTTP header. | |
| Modificada | Crítica (9.8) | 2.4% | — | Strategy11 Formidable Form Builder | 29/8/2019 | 17/6/2026 | The formidable plugin before 4.02.01 for WordPress has unsafe deserialization. | |
| Modificada | Alta (8.8) | 1.1% | — | Web-dorado WP Form Builder | 26/4/2019 | 17/6/2026 | The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is… | |
| Modificada | Crítica (9.8) | 1.6% | — | Validformbuilder Validform Builder | 9/2/2018 | 17/6/2026 | ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute unauthorised system commands remotely and disclose file contents in file system. | |
| Modificada | Crítica (9.8) | 2.5% | — | Accesspressthemes Ultimate-form-builder-lite | 26/10/2017 | 17/6/2026 | The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php. | |
| Modificada | Media (5.3) | 1.6% | — | Cmsmadesimple Form BuilderCmsmadesimple CMS Made Simple | 21/2/2017 | 17/6/2026 | CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin. | |
| Modificada | Media (5.3) | 1.6% | — | Cmsmadesimple Form BuilderCmsmadesimple CMS Made Simple | 21/2/2017 | 17/6/2026 | CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml. | |
| Modificada | Crítica (9.8) | 2.3% | — | Cmsmadesimple Form BuilderCmsmadesimple CMS Made Simple | 21/2/2017 | 17/6/2026 | CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to execute PHP code via the cntnt01fbrp_forma_form_template parameter in admin_store_form. | |
| Modificada | Media (6.1) | 0.77% | — | Fastspot Bigtree-form-builder | 10/2/2017 | 17/6/2026 | An issue was discovered in Fastspot BigTree bigtree-form-builder before 1.2. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP POST parameters passed to a "site/index.php/../../extensions/com.fastspot.form-builder/ajax/redraw-field.php" URL. An attacker could execute… |