Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
289 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.76% | — | Ninjaforms Ninja Forms | 7/12/2023 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress leading to DoS.This issue affects Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: from n/a through 3.6.25. | |
| Modificada | Crítica (9.8) | 0.88% | — | Atomicwebstrategy Woocommerce Ninja Forms Product Add-ons | 6/11/2023 | 17/6/2026 | The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE. | |
| Modificada | Media (4.8) | 0.62% | — | Ninjaforms Ninja Forms | 6/11/2023 | 17/6/2026 | The Ninja Forms Contact Form WordPress plugin before 3.6.34 does not sanitize and escape its label fields, which could allow high privilege users such as admin to perform Stored XSS attacks. Only users with the unfiltered_html capability can perform this, and such users are already allowed to use JS in posts/comments… | |
| Modificada | Media (4.8) | 0.32% | — | Internetmarketingninjas Internal Link Building | 27/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Internet Marketing Ninjas Internal Link Building plugin <= 1.2.3 versions. | |
| Modificada | Media (5.4) | 0.53% | — | Ninjateam Live Chat With Facebook Messenger | 25/10/2023 | 17/6/2026 | The Live Chat with Facebook Messenger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'messenger' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Alta (8.8) | 0.27% | — | Internetmarketingninjas Internal Link Building | 25/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Internet Marketing Ninjas Internal Link Building plugin <= 1.2.3 versions. | |
| Modificada | Media (4.8) | 0.40% | — | Ninjateam Filester | 16/10/2023 | 17/6/2026 | The File Manager Pro WordPress plugin before 1.8.1 does not adequately validate and escape some inputs, leading to XSS by high-privilege users. | |
| Modificada | Alta (7.2) | 1.3% | 💥 PoC | Ninjateam Filester | 16/10/2023 | 17/6/2026 | The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of the server, such as a multisite installation. This leads to remote code execution. | |
| Modificada | Alta (8.8) | 7.9% | — | Ninjateam Filester | 16/10/2023 | 17/6/2026 | The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users perform unwanted file system actions via CSRF attacks by using GET requests, such as uploading a web shell. | |
| Modificada | Media (4.8) | 0.44% | — | Ninjaforms Ninja Forms Contact Form | 30/8/2023 | 17/6/2026 | The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by a HTML Injection security vulnerability. | |
| Modificada | Media (6.1) | 0.38% | — | Commoninja Paytm Payment Donation | 14/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paytm Paytm Payment Donation plugin <= 2.2.0 versions. | |
| Modificada | Media (6.1) | 0.36% | — | Arscode Ninja Popups | 10/8/2023 | 17/6/2026 | Unauth. Open Redirect vulnerability in Arscode Ninja Popups plugin <= 4.7.5 versions. | |
| Modificada | Media (6.1) | 9.7% | 💥 Exploit | Ninjaforms Ninja Forms | 27/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions. | |
| Modificada | Media (6.1) | 0.60% | — | Wpmanageninja Fluentsmtp | 12/7/2023 | 17/6/2026 | The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (6.1) | 0.72% | — | Gsheetconnector Ninja Forms Google Sheet Connector | 4/7/2023 | 17/6/2026 | The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Baja (3.7) | 0.80% | 💥 PoC | Wpmanageninja Fluentcrm | 9/6/2023 | 17/6/2026 | The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 2.8.01 due to the use of an MD5 hash without a salt to control subscriptions. This makes it possible for unauthenticated attackers to unsubscribe users from lists… | |
| Modificada | Crítica (9.8) | 1.7% | — | Ninjateam Gpdr Ccpa Compliance Support | 7/6/2023 | 17/6/2026 | The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_allow_permissions" value. This allows unauthenticated attackers to inject a PHP Object. | |
| Modificada | Crítica (9.8) | 0.60% | — | Itrsgroup Ninja | 28/5/2023 | 17/6/2026 | A vulnerability was found in ITRS Group monitor-ninja up to 2021.11.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file modules/reports/models/scheduled_reports.php. The manipulation leads to sql injection. Upgrading to version 2021.11.30 is able to address this issue.… | |
| Modificada | Alta (8.8) | 0.27% | — | Wpmanageninja Ninja Tables | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPManageNinja LLC Ninja Tables – Best Data Table Plugin for WordPress plugin <= 4.3.4 versions. | |
| Modificada | Media (6.1) | 0.92% | 💥 Exploit | Ninjaforms Ninja Forms | 15/5/2023 | 17/6/2026 | The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (4.8) | 0.42% | — | Wpmanageninja Ninja Tables | 10/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPManageNinja LLC Ninja Tables plugin <= 4.3.4 versions. | |
| Modificada | Media (5.4) | 0.51% | — | Wpmanageninja Fluentsmtp | 13/3/2023 | 17/6/2026 | The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (XSS) when an administrator views the email logs. This exploit requires other plugins to enable users to send emails with unfiltered HTML. | |
| Modificada | Alta (7.5) | 0.73% | — | Wpmanageninja Fluentauth | 23/1/2023 | 17/6/2026 | The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin. | |
| Modificada | Alta (7.2) | 1.4% | — | Ninjaforms Ninja Forms | 26/9/2022 | 17/6/2026 | The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. | |
| Modificada | Alta (7.2) | 1.2% | — | Wpmanageninja Fluent Support | 29/8/2022 | 17/6/2026 | The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection vulnerability exploitable by high privilege users |