Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.32% | — | Gravityforms Gravity FormsAI | 2/5/2026 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a Repeater field. When SingleProduct fields are nested within Repeater… | |
| Aplazada | Alta (7.2) | 0.30% | — | Gravityforms Gravity FormsAI | 2/5/2026 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because the state validation function accepts submitted values where the… | |
| Aplazada | Baja (1.3) | 0.36% | — | Getgrav GravAI | 28/4/2026 | 24/7/2026 | A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The manipulation results in deserialization. The attack may be launched remotely.… | |
| Aplazada | Crítica (9.3) | 0.88% | — | Creolabs GravityAI | 16/4/2026 | 14/7/2026 | Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bounds memory by crafting scripts with many string literals at global scope. Attackers can exploit insufficient bounds checking in gravity_fiber_reassign() to corrupt heap… | |
| Aplazada | Alta (7.1) | 0.35% | — | Gravity SmtpAI | 10/4/2026 | 17/6/2026 | The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to uninstall… | |
| Aplazada | Media (6.4) | 0.24% | — | Magicconversation Magic Conversation FOR Gravity FormsAI | 8/4/2026 | 25/7/2026 | The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'magic-conversation' shortcode in all versions up to, and including, 3.0.97 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (4.7) | 0.39% | 💥 PoC | Gravityforms Gravity FormsAI | 8/4/2026 | 24/7/2026 | The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This is due to the `GFCommon::send_json()` method outputting JSON-encoded data wrapped in HTML comment delimiters using… | |
| Aplazada | Media (6.1) | 0.38% | — | Gravityforms Gravity FormsAI | 8/4/2026 | 24/7/2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`) in all versions up to, and including, 2.9.30. This is due to the `get_value_entry_detail()` method in the `GF_Field_CreditCard` class outputting the card type value… | |
| Aplazada | Alta (7.5) | 2.2% | 💥 Exploit | Gravity SmtpAI | 31/3/2026 | 17/6/2026 | The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor… | |
| Analizada | Alta (7.6) | 0.35% | — | Getgrav Grav | 30/3/2026 | 17/6/2026 | Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin. | |
| Aplazada | Media (6.4) | 0.26% | — | Gravityforms Gravity FormsAI | 11/3/2026 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a compound failure involving missing authorization on the `create_from_template` AJAX endpoint (allowing any authenticated user to create forms), insufficient input… | |
| Analizada | Alta (8.7) | 0.29% | — | Gravitl Netmaker | 7/3/2026 | 17/6/2026 | Netmaker makes networks with WireGuard. Prior to version 1.5.0, a user assigned the platform-user role can retrieve WireGuard private keys of all wireguard configs in a network by calling GET /api/extclients/{network} or GET /api/nodes/{network}. While the Netmaker UI restricts visibility, the API endpoints return… | |
| Analizada | Media (6.9) | 0.33% | — | Gravitl Netmaker | 7/3/2026 | 17/6/2026 | Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lacks validation to prevent an admin-role user from assigning the super-admin role during account updates. While the code correctly blocks an admin from assigning the admin role to another user, it does… | |
| Analizada | Alta (8.6) | 0.47% | — | Gravitl Netmaker | 7/3/2026 | 17/6/2026 | Netmaker makes networks with WireGuard. Prior to version 1.5.0, the Authorize middleware in Netmaker incorrectly validates host JWT tokens. When a route permits host authentication (hostAllowed=true), a valid host token bypasses all subsequent authorization checks without verifying that the host is authorized to… | |
| Aplazada | Alta (7.1) | 0.19% | — | Zack Katz Icontact FOR Gravity FormsAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz iContact for Gravity Forms gravity-forms-icontact allows Reflected XSS.This issue affects iContact for Gravity Forms: from n/a through <= 1.3.2. | |
| Aplazada | Media (5.1) | 0.64% | — | Getgrav GravAIGetgrav Admin PluginAI | 26/1/2026 | 17/6/2026 | Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be executed when the page is viewed in the… | |
| Modificada | Crítica (9.3) | 2.2% | — | Getgrav Grav | 16/1/2026 | 17/6/2026 | GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base64-encoded payloads and create malicious custom jobs with system command… | |
| Aplazada | Media (4.3) | 0.22% | — | Gravityforms Signature Add-onAI | 31/12/2025 | 28/9/2026 | Missing Authorization vulnerability in approveme Signature Add-On for Gravity Forms gravity-signature-forms-add-on allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Signature Add-On for Gravity Forms: from n/a through <= 1.8.6. | |
| Aplazada | Media (6.8) | 0.37% | 💥 PoC | Gravityforms Gravity FormsAI | 24/12/2025 | 17/6/2026 | The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path. | |
| Aplazada | Alta (8.5) | 0.15% | — | Cobian Backup GravityAI | 22/12/2025 | 17/6/2026 | Cobian Backup Gravity 11.2.0.582 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the CobianBackup11 service to inject malicious code that would execute with LocalSystem… | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Salesforce | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue affects WP Gravity Forms Salesforce: from n/a through <= 1.5.1. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Hubspot | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection.This issue affects WP Gravity Forms HubSpot: from n/a through <= 1.2.6. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Constant Contact Plugin | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contact allows Object Injection.This issue affects WP Gravity Forms Constant Contact Plugin: from n/a through <= 1.1.2. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Zoho CRM AND Bigin | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.9. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Insightly | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gravity Forms Insightly: from n/a through <= 1.1.6. |