Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1177 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.61% | — | Wpforms ConnectorAI | 24/6/2026 | 25/6/2026 | The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/list/<id> (callback userDetail()) with permission_callback set to '__return_true', and the function's home-grown authentication only verifies that… | |
| Aplazada | Alta (7.2) | 0.32% | — | Reputeinfosystems ArformsAI | 24/6/2026 | 25/6/2026 | The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save_incomplete_form_data` AJAX action in all versions up to, and including, 7.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (8.1) | 1.0% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 20/6/2026 | 22/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the… | |
| Aplazada | Crítica (9) | 0.40% | — | Sigmaforms PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Quantumcloud Conversational Forms FOR ChatbotAI | 17/6/2026 | 1/10/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue affects Conversational Forms for ChatBot: from n/a through 1.1.8. | |
| Aplazada | Crítica (9.8) | 0.56% | 💥 PoC | Integration FOR Activecampaign AND Contact Form 7 Wpforms Elementor Ninja FormsAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | HappyformsAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | WpformsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | CformsiiAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions. | |
| Aplazada | Media (6.9) | 0.31% | — | Hepta Platforms HeptabaseAI | 12/6/2026 | 29/9/2026 | Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim into opening or loading a malicious webpage within the Heptabase application, thereby gaining unauthorized access to… | |
| Aplazada | Alta (8.8) | 0.27% | — | Wow-company WOW FormsAI | 9/6/2026 | 21/7/2026 | Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. Attackers can inject SQL code through the 'mwpformid' parameter in requests to the admin-ajax.php endpoint with the… | |
| Aplazada | Media (5.3) | 0.33% | — | WpformsAI | 9/6/2026 | 23/7/2026 | The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions. | |
| Aplazada | Media (5.3) | 0.30% | — | WpformsAI | 6/6/2026 | 23/7/2026 | The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to and including 1.10.0.1. This is due to the PayPal Commerce webhook endpoint processing unauthenticated JSON webhook… | |
| Aplazada | Media (4.3) | 0.19% | — | Tectite FormsAI | 2/6/2026 | 22/7/2026 | The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the admin_init function. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the… | |
| Analizada | Media (5.3) | 0.46% | — | Nextcloud Forms | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to uploaded files for forms where that user previously had results access. This issue… | |
| Aplazada | Crítica (9.6) | 0.50% | 💥 PoC | Rocketgenius INC Gravity FormsAI | 1/6/2026 | 22/7/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a through 2.10.0.1. | |
| Aplazada | Media (4.3) | 0.26% | — | Wpeverest Everest FormsAI | 28/5/2026 | 17/6/2026 | The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 3.4.7. This makes it possible for authenticated attackers, with… | |
| Analizada | Crítica (9.3) | 0.38% | — | Tassos Advanced Custom FieldsTassos Convert FormsTassos EngageboxTassos Google Structured Data+4 | 27/5/2026 | 17/6/2026 | The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites. | |
| Aplazada | Alta (7.1) | 0.15% | — | Bgermann CformsiiAI | 25/5/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affects CformsII: from n/a through 15.1.3. | |
| Aplazada | Alta (7.1) | 0.28% | — | ExtroformsAI | 25/5/2026 | 24/7/2026 | Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, and filter_search parameters. Attackers can submit POST requests to the extroformfield view with malicious SQL payloads to extract… | |
| Aplazada | Media (4.3) | 0.40% | — | Vedrixa FormsAI | 22/5/2026 | 23/7/2026 | The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Media (5) | 0.25% | — | Add-ons.org PDF FOR Elementor Forms AND Drag AND Drop Template BuilderAI | 20/5/2026 | 23/7/2026 | Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through 5.5.1. | |
| Aplazada | Crítica (9.8) | 0.87% | 💥 PoC | Piotnet FormsAI | 19/5/2026 | 17/6/2026 | The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including, 2.1.40. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions,… | |
| Aplazada | Media (4.9) | 0.60% | — | Nexton NEX FormsAI | 15/5/2026 | 17/6/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions up to, and including, 9.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Alta (8.2) | 0.38% | — | Fluentforms Fluent FormsAI | 14/5/2026 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to missing validation on a user controlled key. This makes it possible for… |