Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.45% | — | Bitapps BIT FormAI | 14/8/2026 | 17/8/2026 | The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'data[queryCondition]' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of… | |
| Aplazada | Alta (7.5) | 0.37% | — | Bitapps BIT FormAI | 5/8/2026 | 26/8/2026 | The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that executes when the file is viewed, leading to Stored Cross-Site Scripting. | |
| Aplazada | Media (4.8) | 0.24% | — | Bitapps BIT FormAI | 1/8/2026 | 29/9/2026 | The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability on multisite) to store JavaScript that executes in the… | |
| Aplazada | Baja (3.7) | 0.25% | — | Bitapps BIT FormAI | 30/7/2026 | 30/7/2026 | The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished. | |
| Aplazada | Media (6.5) | 0.34% | — | Bitapps BIT FormAI | 21/7/2026 | 21/7/2026 | The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations. | |
| Aplazada | Media (5.9) | 0.40% | — | Bitapps BIT FormAI | 21/7/2026 | 21/7/2026 | The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress configuration file. | |
| Aplazada | Alta (7.1) | 1.1% | — | Bitapps BIT FormAI | 9/7/2026 | 9/7/2026 | The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteFiles function in all versions up to, and including, 3.1.1 This makes it possible for authenticated… | |
| Aplazada | Alta (7.6) | 0.28% | — | Bitapps BIT FormAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection.This issue affects Bit Form: from n/a through <= 2.21.10. | |
| Aplazada | Media (6.5) | 0.42% | — | Bitapps BIT FormAI | 7/1/2026 | 30/9/2026 | The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to unauthorized workflow execution due to missing authorization in the triggerWorkFlow function in all versions up to, and including, 2.21.6. This is due to a logic flaw in the nonce verification where the security check only blocks requests when… | |
| Aplazada | Crítica (9.8) | 0.81% | — | Bitapps BIT FormAI | 15/8/2025 | 17/6/2026 | The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.20.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.… | |
| Analizada | Alta (7.5) | 0.38% | — | Bitapps BIT Form | 2/7/2025 | 17/6/2026 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.17.4 via file uploads due to insufficient directory listing prevention and lack of… | |
| Aplazada | Media (4.9) | 0.29% | — | Bitform Contact Form BY BIT FormAI | 25/4/2025 | 17/6/2026 | The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Aplazada | Media (4.7) | 0.42% | — | Bitapps BIT FormAI | 27/3/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bit Apps Bit Form bit-form allows Phishing.This issue affects Bit Form: from n/a through <= 2.18.0. | |
| Aplazada | Media (4.9) | 0.53% | — | Bitform Contact Form BY BIT FormAI | 11/10/2024 | 17/6/2026 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.15.2 due to improper input validation within the iconUpload function. This makes it possible for… | |
| Aplazada | Alta (7.6) | 0.42% | — | Bitapps BIT FormAI | 7/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection.This issue affects Bit Form: from n/a through <= 2.13.11. | |
| Aplazada | Alta (7.1) | 0.32% | — | Bitapps BIT FormAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bit Apps Bit Form bit-form allows Stored XSS.This issue affects Bit Form: from n/a through <= 2.13.10. | |
| Aplazada | Alta (8) | 0.43% | — | Bitapps BIT FormAI | 5/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form bit-form.This issue affects Bit Form: from n/a through <= 2.13.10. | |
| Analizada | Media (6.5) | 0.42% | — | Bitapps BIT Form | 26/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bit Apps Bit Form Pro.This issue affects Bit Form Pro: from n/a through 2.6.4. | |
| Analizada | Media (6.5) | 0.29% | — | Bitapps BIT Form | 19/8/2024 | 17/6/2026 | Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bit Form Pro: from n/a through 2.6.4. | |
| Analizada | Alta (8.8) | 1.0% | — | Bitapps BIT Form | 19/8/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This issue affects Bit Form Pro: from n/a through 2.6.4. | |
| Analizada | Crítica (9.1) | 0.59% | — | Bitapps BIT Form | 19/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro allows File Manipulation.This issue affects Bit Form Pro: from n/a through 2.6.4. | |
| Aplazada | Alta (7.2) | 0.96% | — | Bitapps BIT FormAI | 9/7/2024 | 17/6/2026 | The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'iconUpload' function in all versions up to, and including, 2.13.3. This makes it possible for authenticated attackers, with administrator-level and above permissions, to upload arbitrary files on the… | |
| Modificada | Crítica (9.8) | 1.8% | — | Bitapps BIT Form | 15/5/2023 | 17/6/2026 | The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution. |