Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
1178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.6) | 0.87% | — | HappyformsAI | 10/7/2026 | 29/9/2026 | The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.26.12 via the happyforms_get_form_partial() function. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.1) | 0.36% | — | Brevo Newsletter Smtp Email Marketing Subscribe FormsAI | 10/7/2026 | 10/7/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.47% | — | Sureforms Drag AND Drop Form BuilderAI | 10/7/2026 | 14/7/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 2.2.1. This is due to the plugin accepting the payment amount directly from user-controlled POST data in the 'create_payment_intent' and… | |
| Aplazada | Media (5.4) | 0.30% | — | Fluentcrm Fluent FormsAI | 10/7/2026 | 10/7/2026 | The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX flow. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.8) | 5.1% | 💥 Exploit | Super-forms Super FormsAI | 10/7/2026 | 10/7/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only… | |
| Aplazada | Alta (7.2) | 0.32% | — | WP Cost Estimation Payment Forms BuilderAI | 9/7/2026 | 9/7/2026 | The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versions up to, and including, 10.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Analizada | Crítica (10) | 15% | ⚠ Explotación activa💥 Exploit | Balbooa Forms | 9/7/2026 | 24/7/2026 | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. | |
| Aplazada | Media (6.5) | 0.30% | — | Wpeverest Everest FormsAI | 9/7/2026 | 9/7/2026 | The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check is only applied when an attacker-controllable request header holds a specific value, so it can be bypassed by omitting or changing that header.… | |
| Aplazada | Alta (7.5) | 0.43% | — | Wpeverest Everest FormsAI | 9/7/2026 | 9/7/2026 | The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable… | |
| Aplazada | Alta (7.5) | 0.48% | — | Notifications FOR Forms AND Wordpress ActionsAI | 6/7/2026 | 6/7/2026 | The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to build a server-side file inclusion path, allowing authenticated users with subscriber-level access and above to include and execute arbitrary local PHP files on the server. | |
| Aplazada | Alta (7.2) | 0.53% | — | NEX FormsAI | 3/7/2026 | 7/7/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (5.3) | 0.35% | — | Ninjaforms Ninja Forms File UploadsAI | 3/7/2026 | 6/7/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read all plugin debug log… | |
| Aplazada | Alta (7.5) | 0.60% | — | Ninjaforms Ninja Forms File UploadsAI | 2/7/2026 | 2/7/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and including, 3.3.29. This is due to the get_files_for_attachment() function accepting a raw attacker-controlled 'files' array when the process() method returns early due to a… | |
| Aplazada | Baja (2.7) | 0.28% | — | Fluentforms Fluent FormsAI | 2/7/2026 | 2/7/2026 | The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage, allowing a Manager limited to specific forms to permanently delete submission entries belonging to other forms. This requires a non-default… | |
| Aplazada | Alta (7.2) | 0.53% | — | NexformsAI | 1/7/2026 | 1/7/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array Parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (7.5) | 0.48% | — | Ninjaforms Ninja FormsAI | 1/7/2026 | 1/7/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers… | |
| Aplazada | Baja (3.1) | 0.21% | — | Fluentcrm Fluent FormsAI | 1/7/2026 | 1/7/2026 | The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users. | |
| Aplazada | Media (6.4) | 0.42% | — | Kaliforms Kali FormsAI | 1/7/2026 | 1/7/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.60% | — | WpformsAI | 1/7/2026 | 1/7/2026 | The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 1.10.2 This is due to `get_reply_to_address()` processing the Reply-To display name… | |
| Aplazada | Media (5.9) | 0.24% | — | KaliformsAI | 30/6/2026 | 30/6/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store JavaScript that executes in an administrator's… | |
| Aplazada | Alta (7.1) | 0.25% | — | Reputeinfosystems ArformsAI | 29/6/2026 | 29/6/2026 | Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions. | |
| Aplazada | Media (5.3) | 0.49% | — | Basixonline Nex-formsAI | 27/6/2026 | 29/6/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enumerate… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpeverest Everest FormsAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Toolset FormsAI | 26/6/2026 | 26/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions. | |
| Aplazada | Media (6.5) | 0.40% | — | Gravityforms BookingAI | 25/6/2026 | 25/6/2026 | The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… |