Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

264 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.2%—Crmperks Database FOR Contact Form 7, Wpforms, Elementor Forms31/1/202417/6/2026
The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on…
ModificadaMedia (6.5)0.28%—Renzojohnson Contact Form 7 Extension FOR Mailchimp24/1/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp.This issue affects Contact Form 7 Extension For Mailchimp: from n/a through 0.5.70.
ModificadaMedia (6.1)0.45%—Ari-soft Contact Form 7 Connector16/1/202417/6/2026
The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against administrators.
ModificadaAlta (7.8)0.43%—Crmperks Database FOR Contact Form 7, Wpforms, Elementor Forms16/1/202417/6/2026
The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.
ModificadaMedia (4.3)0.35%—Rocklobster Contact Form 711/1/202417/6/2026
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the CF7_get_custom_field and CF7_get_current_user shortcodes due to missing validation on a user controlled key. This makes it possible for authenticated…
ModificadaMedia (6.1)0.36%—Crmperks Database FOR Contact Form 7, Wpforms, Elementor Forms29/12/202317/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.2.8.
ModificadaAlta (8.1)0.63%—Themefic Ultimate Addons FOR Contact Form 720/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Ultimate Addons for Contact Form 7.This issue affects Ultimate Addons for Contact Form 7: from n/a through 3.1.23.
ModificadaMedia (6.1)0.48%—Crmperks Integration FOR Salesforce AND Contact Form 7, Wpforms, Elementor, Ninja Forms19/12/202317/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for Salesforce and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Salesforce and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.3.3.
ModificadaMedia (4.8)0.44%—Codesmade Autocomplete Location Field Contact Form 718/12/202317/6/2026
The Autocomplete Location field Contact Form 7 WordPress plugin before 3.0, autocomplete-location-field-contact-form-7-pro WordPress plugin before 2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the…
ModificadaMedia (4.8)0.39%—Zealousweb Track Geolocation OF Users Using Contact Form 715/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZealousWeb Track Geolocation Of Users Using Contact Form 7 allows Stored XSS.This issue affects Track Geolocation Of Users Using Contact Form 7: from n/a through 2.0.
ModificadaMedia (6.1)0.40%—Themefic Ultimate Addons FOR Contact Form 714/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Ultimate Addons for Contact Form 7 allows Stored XSS.This issue affects Ultimate Addons for Contact Form 7: from n/a through 3.2.0.
ModificadaMedia (6.1)0.38%—Crmperks Integration FOR Constant Contact AND Contact Form 7, Wpforms, Elementor, Ninja7/12/202317/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks. Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.1.4.
ModificadaMedia (6.1)0.44%—Bannersky BSK Contact Form 7 Blacklist4/12/202317/6/2026
The BSK Contact Form 7 Blacklist WordPress plugin through 1.0.1 does not sanitise and escape the inserted_count parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaAlta (7.2)1.7%—Rocklobster Contact Form 71/12/202317/6/2026
The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function and insufficient blocklisting on the 'wpcf7_antiscript_file_name' function in versions up to, and including, 5.8.3. This makes it possible for authenticated attackers with…
ModificadaCrítica (9.8)1.8%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 722/11/202317/6/2026
The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for unauthenticated attackers to upload arbitrary files…
ModificadaCrítica (9.8)0.70%—Rocklobster Contact Form 7 Custom Validation6/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aiyaz, maheshpatel Contact form 7 Custom validation allows SQL Injection.This issue affects Contact form 7 Custom validation: from n/a through 1.1.3.
ModificadaCrítica (9.8)0.74%—Crmperks Database FOR Contact Form 7, Wpforms, Elementor Forms31/10/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms, Elementor forms contact-form-entries allows SQL Injection.This issue affects Database for Contact Form 7, WPforms, Elementor forms: from n/a through 1.3.0.
ModificadaMedia (6.1)0.39%—Themefic Ultimate Addons FOR Contact Form 727/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.2.0 versions.
ModificadaMedia (6.1)0.49%—Themefic Ultimate Addons FOR Contact Form 714/8/202317/6/2026
The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
ModificadaMedia (4.8)0.47%—Themefic Ultimate Addons FOR Contact Form 714/8/202317/6/2026
The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (8.8)0.31%—Wpplugin Contact Form 7 Redirect & Thank YOU Page10/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 Redirect & Thank You Page plugin <= 1.0.3 versions.
ModificadaMedia (4.3)0.46%—Cf7style Contact Form 7 Style1/7/202317/6/2026
The Contact Form 7 Style plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2. This is due to missing or incorrect nonce validation on the manage_wp_posts_be_qe_save_post() function. This makes it possible for unauthenticated attackers to quick edit templates via a…
ModificadaCrítica (9.8)0.65%—Themefic Ultimate Addons FOR Contact Form 719/6/202317/6/2026
Unauth. SQL Injection (SQLi) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.1.23 versions.
ModificadaMedia (4.8)0.44%—Crmperks Integration FOR Contact Form 7 AND Zoho Crm, Bigin19/6/202317/6/2026
The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
ModificadaMedia (6.1)0.38%—Zestard Admin Side Data Storage FOR Contact Form 715/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact Form 7 plugin <= 1.1.1 versions.