Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | Formidable Forms Signature Online Contract AutomationAI | 6/8/2026 | 12/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | WP Full PAY Stripe Payment FormsAI | 6/8/2026 | 26/8/2026 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every public page containing a payment form — to… | |
| Aplazada | Alta (8.1) | 0.49% | — | Mailchimp Forms BY MailmunchAI | 5/8/2026 | 12/8/2026 | The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Crítica (9.1) | 0.66% | — | Gravity Forms Multi Uploader Multi Uploader FOR Gravity FormsAI | 5/8/2026 | 12/8/2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via `wp_ajax_nopriv_gfmu_delete_file`. The nonce… | |
| Aplazada | Media (6.8) | 0.39% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 4/8/2026 | 26/8/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated… | |
| Aplazada | Media (6.1) | 0.37% | — | Fluentforms Fluent FormsAI | 1/8/2026 | 12/8/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'param' in all versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.1) | 1.2% | — | Kaliforms Kali FormsAI | 1/8/2026 | 12/8/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder,… | |
| Aplazada | Alta (8.1) | 0.58% | — | NEX FormsAI | 1/8/2026 | 12/8/2026 | The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no… | |
| Aplazada | Media (5.3) | 0.56% | — | Gutena FormsAI | 1/8/2026 | 12/8/2026 | The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.9.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Alta (8.1) | 0.38% | — | Login Register FormsAI | 1/8/2026 | 26/8/2026 | The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthenticated attackers to reset the limit at… | |
| Aplazada | Media (6.4) | 0.36% | — | Brainstormforce SureformsAI | 1/8/2026 | 12/8/2026 | The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headingWrapper' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.63% | — | Fluentforms Fluent FormsAI | 31/7/2026 | 12/8/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.25% | — | Fluentforms Fluent FormsAI | 30/7/2026 | 30/7/2026 | The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the… | |
| Aplazada | Alta (7.2) | 0.53% | — | Fluentcrm Fluent FormsAI | 29/7/2026 | 30/7/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Crítica (10) | 0.77% | — | Balbooa FormsAI | 28/7/2026 | 28/7/2026 | Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type. | |
| Aplazada | Alta (7.1) | 0.25% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 28/7/2026 | 28/7/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.1) | 0.25% | — | Kali FormsAI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions. | |
| Aplazada | Alta (8.8) | 0.55% | — | Fluent Forms PRO ADD ON PackAI | 26/7/2026 | 27/7/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of… | |
| Aplazada | Alta (8.1) | 2.5% | — | Wpforms PROAI | 25/7/2026 | 27/7/2026 | The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not… | |
| Aplazada | Media (4.9) | 0.51% | — | Ninjaforms Ninja FormsAI | 24/7/2026 | 24/7/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Pendiente de análisis | Media (5.3) | 0.44% | — | Oracle JavaAIRedhat Cloudforms SystemAI | 23/7/2026 | 24/7/2026 | An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary. | |
| Aplazada | Alta (7.1) | 0.25% | — | Form Vibes Database Manager FOR FormsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. | |
| Aplazada | Alta (7.7) | 0.47% | — | Kali FormsAI | 23/7/2026 | 23/7/2026 | Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions. | |
| Aplazada | Crítica (9.6) | 0.20% | — | Ninjaforms File Uploads ExtensionAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpforms Download MonitorAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions. |