Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
1178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.2) | 0.44% | — | Hepta Platforms INC HeptabaseAI | 24/8/2026 | 26/8/2026 | Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary JavaScript code to execute when other users click the crafted content. | |
| Aplazada | Media (6.6) | 0.36% | — | Wpmudev Forminator FormsAI | 22/8/2026 | 26/8/2026 | The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it. | |
| Aplazada | Alta (7.2) | 0.34% | — | Wpforms PROAI | 21/8/2026 | 24/8/2026 | The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all versions up to, and including, 2.0.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.9) | 0.45% | — | Tassos Convert FormsAIJoomlaAI | 20/8/2026 | 26/8/2026 | Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions. | |
| Aplazada | Alta (7.7) | 0.56% | — | Balbooa FormsAI | 19/8/2026 | 26/8/2026 | Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it from the form's configured product prices. Neither… | |
| Aplazada | Crítica (10) | 0.50% | — | Balbooa FormsAI | 19/8/2026 | 29/9/2026 | Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject… | |
| Aplazada | Alta (8.8) | 0.56% | — | Brainstormforce SureformsAI | 18/8/2026 | 3/9/2026 | CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is… | |
| Aplazada | Alta (7.5) | 0.58% | — | Brainstormforce SureformsAI | 18/8/2026 | 3/9/2026 | The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface,… | |
| Aplazada | Media (6.5) | 0.22% | — | Wpzoom Forms Contact Form Plugin FOR GutenbergAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Gravityforms BookingsAI | 18/8/2026 | 20/8/2026 | Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mdmag Quill FormsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. | |
| Aplazada | Alta (7.2) | 0.32% | — | Mdmag Quill FormsAI | 18/8/2026 | 20/8/2026 | The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Crítica (9.8) | 0.76% | — | Reputeinfosystems ArformsAI | 16/8/2026 | 1/10/2026 | The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP… | |
| Aplazada | Media (4.9) | 0.44% | — | NexformsAI | 16/8/2026 | 20/8/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Media (4.3) | 0.47% | — | Wpeverest Everest FormsAI | 16/8/2026 | 20/8/2026 | The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Crítica (9.3) | 0.67% | — | Fluent Forms PROAI | 13/8/2026 | 9/9/2026 | Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a… | |
| Aplazada | Alta (7.1) | 0.25% | — | Mailchimp Subscribe FormsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions. | |
| Aplazada | Alta (7.2) | 0.49% | — | Fluentform Fluent FormsAI | 13/8/2026 | 14/8/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode Values in all versions up to, and including, 6.2.11 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Alta (7.5) | 0.43% | — | Login AND Register FormsAI | 10/8/2026 | 26/8/2026 | The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not adequately redact the address returned in its response, allowing unauthenticated users to obtain registered users' email addresses, including administrators'. | |
| Aplazada | Alta (8.1) | 0.38% | — | Login Register FormsAI | 10/8/2026 | 26/8/2026 | The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying both the verification code and the per-source attempt counter on client-controlled data, allowing unauthenticated attackers to reset the limit at will and brute-force the… | |
| Aplazada | Alta (8.1) | 0.38% | — | Login Register FormsAI | 10/8/2026 | 26/8/2026 | The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently… | |
| Aplazada | Media (4.8) | 0.24% | — | Ninjaforms Ninja FormsAI | 6/8/2026 | 26/8/2026 | The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a… | |
| Aplazada | Media (5.9) | 0.18% | — | Strategy11 Formidable FormsAI | 6/8/2026 | 26/8/2026 | The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without… | |
| Aplazada | Media (6.5) | 0.42% | — | Gutena FormsAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions. |