Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | CformsiiAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Bgermann CformsiiAI | 25/5/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affects CformsII: from n/a through 15.1.3. | |
| Aplazada | Media (4.3) | 0.13% | — | CformsAI | 27/9/2025 | 17/6/2026 | The cForms – Light speed fast Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the cforms_api function. This makes it possible for unauthenticated attackers to modify forms and their… | |
| Aplazada | Alta (7.1) | 0.37% | — | Oliver Seidel CformsiiAIBastian Germann CformsiiAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann CformsII allows Stored XSS.This issue affects CformsII: from n/a through 15.0.5. | |
| Modificada | Media (4.8) | 0.32% | — | Cformsii Project Cformsii | 8/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a through 15.0.5. | |
| Modificada | Alta (8.8) | 0.27% | — | Cformsii Project Cformsii | 15/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions. | |
| Modificada | Media (6.1) | 0.91% | — | Cformsii Project Cformsii | 22/8/2019 | 17/6/2026 | The cforms2 plugin before 10.5 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.93% | — | Cformsii Project Cformsii | 22/8/2019 | 17/6/2026 | The cforms2 plugin before 10.2 for WordPress has XSS. | |
| Modificada | Crítica (9.8) | 1.8% | — | Cformsii Project Cformsii | 22/8/2019 | 17/6/2026 | The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries. | |
| Modificada | Crítica (9.8) | 1.8% | — | Cformsii Project Cformsii | 22/8/2019 | 17/6/2026 | The cforms2 plugin before 14.6.10 for WordPress has SQL injection. | |
| Modificada | Media (6.1) | 0.92% | — | Cformsii Project Cformsii | 21/8/2019 | 17/6/2026 | The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 0.93% | — | Cformsii Project Cformsii | 21/8/2019 | 17/6/2026 | The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php. | |
| Modificada | Alta (8.8) | 0.74% | — | Cformsii Project Cformsii | 20/8/2019 | 17/6/2026 | The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field. | |
| Modificada | Media (4.3) | 1.7% | — | Semanticforms Project Semanticforms | 1/9/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the SemanticForms extension for MediaWiki allow remote attackers to inject arbitrary web script or HTML via the (1) wpSummary parameter to Special:FormEdit, the (2) "Template label (optional)" field in a form, or a (3) Field name in a template. | |
| Modificada | Media (4.3) | 1.4% | — | Semanticforms Project Semanticforms | 1/9/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the SemanticForms extension for MediaWiki allow remote attackers to inject arbitrary web script or HTML via a (1) section_*, (2) template_*, (3) label_*, or (4) new_template parameter to Special:CreateForm or (5) target or (6) alt_form parameter to… | |
| Modificada | Alta (7.5) | 14% | — | Deliciousdays Cformsii | 8/1/2015 | 17/6/2026 | Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file via a direct request to the file in the default… | |
| Modificada | Media (4.3) | 4.2% | — | Deliciousdays Cforms | 3/11/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters. | |
| Modificada | Media (6.8) | 2.0% | — | Contact Forms Cforms | 4/2/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in cforms-css.php in Oliver Seidel cforms (contactforms), a Wordpress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the tm parameter. NOTE: CVE disputes this issue for 7.3, since there is no tm parameter, and the code exits with a fatal error due to… |