Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
289 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.53% | — | Ninjaforms NinjascannerAI | 31/7/2025 | 17/6/2026 | The NinjaScanner – Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'nscan_ajax_quarantine' and 'nscan_quarantine_select' functions in all versions up to, and including, 3.2.5. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.9) | 0.64% | — | THE Security NinjaAI | 24/7/2025 | 17/6/2026 | The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.242 via the 'get_file_source' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to extract sensitive data,… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Integration FOR Google Sheets AND Contact Form 7 Wpforms Elementor Ninja FormsAI | 19/7/2025 | 17/6/2026 | The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.1 via deserialization of untrusted input within the verify_field_val() function. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.23% | — | Aman Popup Popup Addon FOR Ninja FormsAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman Popup addon for Ninja Forms popup-addon-for-ninja-forms allows DOM-Based XSS.This issue affects Popup addon for Ninja Forms: from n/a through <= 3.4. | |
| Analizada | Media (5.4) | 0.24% | — | Ninjaforms Ninja Forms | 27/6/2025 | 17/6/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to insufficient output escaping on user data passed through the template. This makes it possible for… | |
| Analizada | Alta (7.2) | 0.33% | — | Wpmanageninja Ninja Tables | 27/6/2025 | 17/6/2026 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.18 via the args[url] parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application… | |
| Aplazada | Media (5.9) | 0.20% | — | Ninjateam File Manager PROAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team File Manager Pro filester allows Stored XSS.This issue affects File Manager Pro: from n/a through <= 1.8.8. | |
| Analizada | Media (5.6) | 0.50% | — | Wpmanageninja Ninja Tables | 3/6/2025 | 17/6/2026 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional… | |
| Analizada | Media (5.4) | 0.27% | — | Ninjateam Chat FOR Telegram | 30/5/2025 | 17/6/2026 | The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (5.3) | 0.31% | — | Integration FOR Salesforce AND Contact Form 7 Wpforms Elementor Formidable Ninja FormsAI | 30/5/2025 | 17/6/2026 | The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used… | |
| Aplazada | Media (4.3) | 0.25% | — | Ninjateam Gdpr Ccpa Compliance SupportAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GDPR CCPA Compliance Support: from n/a through <= 2.7.3. | |
| Modificada | Media (4.8) | 0.25% | — | Ninjaforms Ninja Forms | 19/5/2025 | 17/6/2026 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.8) | 0.25% | — | Ninjaforms Ninja Forms | 19/5/2025 | 17/6/2026 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.8) | 0.30% | — | Ninjaforms Ninja Forms | 19/5/2025 | 17/6/2026 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (5.4) | 0.25% | — | Ninja Pages Project Ninja Pages | 15/5/2025 | 17/6/2026 | The Ninja Pages WordPress plugin through 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.5) | 0.24% | — | Ninja Forms WebhooksAI | 14/5/2025 | 17/6/2026 | The Ninja Forms Webhooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.7 via the form webhook functionality. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations… | |
| Aplazada | Media (4.3) | 0.19% | — | Crmperks WP Zendesk FOR Contact Form 7 Wpforms Elementor Formidable AND Ninja FormsAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-zendesk allows Cross Site Request Forgery.This issue affects WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through <= 1.1.3. | |
| Aplazada | Media (6.5) | 0.22% | — | WP CMS Ninja Norse Runes OracleAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP CMS Ninja Norse Rune Oracle Plugin norse-runes-oracle allows Stored XSS.This issue affects Norse Rune Oracle Plugin: from n/a through <= 1.4.3. | |
| Aplazada | Media (6.5) | 0.20% | — | Ninjateam Click TO Chat WP Support ALL IN ONE Floating WidgetAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget support-chat allows Stored XSS.This issue affects Click to Chat – WP Support All-in-One Floating Widget: from n/a through <= 2.3.4. | |
| Aplazada | Media (5.9) | 0.21% | — | Commoninja Paytm Payment DonationAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in integrationdevpaytm Paytm Payment Donation paytm-donation allows Stored XSS.This issue affects Paytm Payment Donation: from n/a through <= 2.3.3. | |
| Modificada | Alta (7.5) | 0.43% | — | Wpmanageninja Fluent Support | 1/3/2025 | 17/6/2026 | The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via the 'fluent-support' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the… | |
| Modificada | Alta (7.2) | 0.41% | — | Ninjateam Filebird | 25/2/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through <= 6.4.2.1. | |
| Aplazada | Media (6.5) | 0.27% | — | Pankaj Mondal Profile Widget NinjaAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pankaj Mondal Profile Widget Ninja profile-widget-ninja allows DOM-Based XSS.This issue affects Profile Widget Ninja: from n/a through <= 4.3. | |
| Aplazada | Alta (7.1) | 0.26% | — | Commoninja Paytm Payment DonationAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in integrationdevpaytm Paytm Payment Donation paytm-donation allows Reflected XSS.This issue affects Paytm Payment Donation: from n/a through <= 2.3.1. | |
| Analizada | Media (5.4) | 0.33% | — | Wpmanageninja Ninja Tables | 31/1/2025 | 17/6/2026 | The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, leading to a Cross Site Scripting vulnerability. |