Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1178 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.39%—Formidable Forms Signature Online Contract AutomationAI6/8/202612/8/2026
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.
AplazadaAlta (7.5)0.35%—WP Full PAY Stripe Payment FormsAI6/8/202626/8/2026
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every public page containing a payment form — to…
AplazadaAlta (8.1)0.49%—Mailchimp Forms BY MailmunchAI5/8/202612/8/2026
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaCrítica (9.1)0.66%—Gravity Forms Multi Uploader Multi Uploader FOR Gravity FormsAI5/8/202612/8/2026
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via `wp_ajax_nopriv_gfmu_delete_file`. The nonce…
AplazadaMedia (6.8)0.39%—Database FOR Contact Form 7 Wpforms Elementor FormsAI4/8/202626/8/2026
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated…
AplazadaMedia (6.1)0.37%—Fluentforms Fluent FormsAI1/8/202612/8/2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'param' in all versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaAlta (8.1)1.2%—Kaliforms Kali FormsAI1/8/202612/8/2026
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder,…
AplazadaAlta (8.1)0.58%—NEX FormsAI1/8/202612/8/2026
The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no…
AplazadaMedia (5.3)0.56%—Gutena FormsAI1/8/202612/8/2026
The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.9.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
AplazadaAlta (8.1)0.38%—Login Register FormsAI1/8/202626/8/2026
The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthenticated attackers to reset the limit at…
AplazadaMedia (6.4)0.36%—Brainstormforce SureformsAI1/8/202612/8/2026
The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headingWrapper' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (5.3)0.63%—Fluentforms Fluent FormsAI31/7/202612/8/2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing validation on a user controlled key. This makes it possible for…
AplazadaMedia (6.1)0.25%—Fluentforms Fluent FormsAI30/7/202630/7/2026
The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the…
AplazadaAlta (7.2)0.53%—Fluentcrm Fluent FormsAI29/7/202630/7/2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it…
AplazadaCrítica (10)0.77%—Balbooa FormsAI28/7/202628/7/2026
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.
AplazadaAlta (7.1)0.25%—Database FOR Contact Form 7 Wpforms Elementor FormsAI28/7/202628/7/2026
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaAlta (7.1)0.25%—Kali FormsAI27/7/202628/7/2026
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
AplazadaAlta (8.8)0.55%—Fluent Forms PRO ADD ON PackAI26/7/202627/7/2026
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of…
AplazadaAlta (8.1)2.5%—Wpforms PROAI25/7/202627/7/2026
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not…
AplazadaMedia (4.9)0.51%—Ninjaforms Ninja FormsAI24/7/202624/7/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
Pendiente de análisisMedia (5.3)0.44%—Oracle JavaAIRedhat Cloudforms SystemAI23/7/202624/7/2026
An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.
AplazadaAlta (7.1)0.25%—Form Vibes Database Manager FOR FormsAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
AplazadaAlta (7.7)0.47%—Kali FormsAI23/7/202623/7/2026
Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
AplazadaCrítica (9.6)0.20%—Ninjaforms File Uploads ExtensionAI23/7/202623/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
AplazadaAlta (7.1)0.25%—Wpforms Download MonitorAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.