Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

1178 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.6)0.87%—HappyformsAI10/7/202629/9/2026
The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.26.12 via the happyforms_get_form_partial() function. This makes it possible for authenticated attackers,…
AplazadaMedia (6.1)0.36%—Brevo Newsletter Smtp Email Marketing Subscribe FormsAI10/7/202610/7/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (7.5)0.47%—Sureforms Drag AND Drop Form BuilderAI10/7/202614/7/2026
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 2.2.1. This is due to the plugin accepting the payment amount directly from user-controlled POST data in the 'create_payment_intent' and…
AplazadaMedia (5.4)0.30%—Fluentcrm Fluent FormsAI10/7/202610/7/2026
The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX flow. This makes it possible for authenticated attackers, with…
AplazadaCrítica (9.8)5.1%💥 ExploitSuper-forms Super FormsAI10/7/202610/7/2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only…
AplazadaAlta (7.2)0.32%—WP Cost Estimation Payment Forms BuilderAI9/7/20269/7/2026
The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versions up to, and including, 10.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
AnalizadaCrítica (10)15%⚠ Explotación activa💥 ExploitBalbooa Forms9/7/202624/7/2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
AplazadaMedia (6.5)0.30%—Wpeverest Everest FormsAI9/7/20269/7/2026
The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check is only applied when an attacker-controllable request header holds a specific value, so it can be bypassed by omitting or changing that header.…
AplazadaAlta (7.5)0.43%—Wpeverest Everest FormsAI9/7/20269/7/2026
The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable…
AplazadaAlta (7.5)0.48%—Notifications FOR Forms AND Wordpress ActionsAI6/7/20266/7/2026
The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to build a server-side file inclusion path, allowing authenticated users with subscriber-level access and above to include and execute arbitrary local PHP files on the server.
AplazadaAlta (7.2)0.53%—NEX FormsAI3/7/20267/7/2026
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (5.3)0.35%—Ninjaforms Ninja Forms File UploadsAI3/7/20266/7/2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read all plugin debug log…
AplazadaAlta (7.5)0.60%—Ninjaforms Ninja Forms File UploadsAI2/7/20262/7/2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and including, 3.3.29. This is due to the get_files_for_attachment() function accepting a raw attacker-controlled 'files' array when the process() method returns early due to a…
AplazadaBaja (2.7)0.28%—Fluentforms Fluent FormsAI2/7/20262/7/2026
The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage, allowing a Manager limited to specific forms to permanently delete submission entries belonging to other forms. This requires a non-default…
AplazadaAlta (7.2)0.53%—NexformsAI1/7/20261/7/2026
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array Parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaAlta (7.5)0.48%—Ninjaforms Ninja FormsAI1/7/20261/7/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers…
AplazadaBaja (3.1)0.21%—Fluentcrm Fluent FormsAI1/7/20261/7/2026
The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users.
AplazadaMedia (6.4)0.42%—Kaliforms Kali FormsAI1/7/20261/7/2026
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (5.3)0.60%—WpformsAI1/7/20261/7/2026
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 1.10.2 This is due to `get_reply_to_address()` processing the Reply-To display name…
AplazadaMedia (5.9)0.24%—KaliformsAI30/6/202630/6/2026
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store JavaScript that executes in an administrator's…
AplazadaAlta (7.1)0.25%—Reputeinfosystems ArformsAI29/6/202629/6/2026
Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.
AplazadaMedia (5.3)0.49%—Basixonline Nex-formsAI27/6/202629/6/2026
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enumerate…
AplazadaAlta (7.1)0.25%—Wpeverest Everest FormsAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.
AplazadaAlta (7.5)0.43%—Toolset FormsAI26/6/202626/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.
AplazadaMedia (6.5)0.40%—Gravityforms BookingAI25/6/202625/6/2026
The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
Orbitaley — Vulnerabilidades