Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

1177 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.61%—Wpforms ConnectorAI24/6/202625/6/2026
The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/list/<id> (callback userDetail()) with permission_callback set to '__return_true', and the function's home-grown authentication only verifies that…
AplazadaAlta (7.2)0.32%—Reputeinfosystems ArformsAI24/6/202625/6/2026
The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save_incomplete_form_data` AJAX action in all versions up to, and including, 7.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
AplazadaAlta (8.1)1.0%—Database FOR Contact Form 7 Wpforms Elementor FormsAI20/6/202622/6/2026
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the…
AplazadaCrítica (9)0.40%—Sigmaforms PROAI17/6/202617/6/2026
Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.
AplazadaAlta (7.5)0.43%—Quantumcloud Conversational Forms FOR ChatbotAI17/6/20261/10/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue affects Conversational Forms for ChatBot: from n/a through 1.1.8.
AplazadaCrítica (9.8)0.56%💥 PoCIntegration FOR Activecampaign AND Contact Form 7 Wpforms Elementor Ninja FormsAI15/6/202617/6/2026
Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.
AplazadaCrítica (9.8)0.56%—HappyformsAI15/6/202617/6/2026
Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.
AplazadaAlta (7.5)0.35%—WpformsAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
AplazadaAlta (7.1)0.25%—CformsiiAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions.
AplazadaMedia (6.9)0.31%—Hepta Platforms HeptabaseAI12/6/202629/9/2026
Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim into opening or loading a malicious webpage within the Heptabase application, thereby gaining unauthorized access to…
AplazadaAlta (8.8)0.27%—Wow-company WOW FormsAI9/6/202621/7/2026
Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. Attackers can inject SQL code through the 'mwpformid' parameter in requests to the admin-ajax.php endpoint with the…
AplazadaMedia (5.3)0.33%—WpformsAI9/6/202623/7/2026
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.
AplazadaMedia (5.3)0.30%—WpformsAI6/6/202623/7/2026
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to and including 1.10.0.1. This is due to the PayPal Commerce webhook endpoint processing unauthenticated JSON webhook…
AplazadaMedia (4.3)0.19%—Tectite FormsAI2/6/202622/7/2026
The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the admin_init function. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the…
AnalizadaMedia (5.3)0.46%—Nextcloud Forms1/6/202622/7/2026
Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to uploaded files for forms where that user previously had results access. This issue…
AplazadaCrítica (9.6)0.50%💥 PoCRocketgenius INC Gravity FormsAI1/6/202622/7/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a through 2.10.0.1.
AplazadaMedia (4.3)0.26%—Wpeverest Everest FormsAI28/5/202617/6/2026
The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 3.4.7. This makes it possible for authenticated attackers, with…
AnalizadaCrítica (9.3)0.38%—Tassos Advanced Custom FieldsTassos Convert FormsTassos EngageboxTassos Google Structured Data+427/5/202617/6/2026
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
AplazadaAlta (7.1)0.15%—Bgermann CformsiiAI25/5/202624/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affects CformsII: from n/a through 15.1.3.
AplazadaAlta (7.1)0.28%—ExtroformsAI25/5/202624/7/2026
Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, and filter_search parameters. Attackers can submit POST requests to the extroformfield view with malicious SQL payloads to extract…
AplazadaMedia (4.3)0.40%—Vedrixa FormsAI22/5/202623/7/2026
The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…
AplazadaMedia (5)0.25%—Add-ons.org PDF FOR Elementor Forms AND Drag AND Drop Template BuilderAI20/5/202623/7/2026
Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through 5.5.1.
AplazadaCrítica (9.8)0.87%💥 PoCPiotnet FormsAI19/5/202617/6/2026
The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including, 2.1.40. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions,…
AplazadaMedia (4.9)0.60%—Nexton NEX FormsAI15/5/202617/6/2026
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions up to, and including, 9.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
AplazadaAlta (8.2)0.38%—Fluentforms Fluent FormsAI14/5/202617/6/2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to missing validation on a user controlled key. This makes it possible for…
Orbitaley — Vulnerabilidades