Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

264 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.2)0.32%—Magic Tooltips FOR Contact Form 7AI3/10/20263/10/2026
The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 1.0.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (5.3)0.20%—Wpexperts Contact Form 7 HoneypotAI1/10/20261/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in WPExperts CF7 Apps contact-form-7-honeypot allows Retrieve Embedded Sensitive Data.This issue affects CF7 Apps: from n/a through 3.7.2.
AplazadaAlta (7.2)0.24%—Bizessentials Business Essentials FOR Contact Form 7AI1/10/20261/10/2026
The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (7.2)0.40%—Themefic Ultimate Addons FOR Contact Form 7AI30/9/202630/9/2026
Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions.
AplazadaCrítica (9.8)1.1%—Ultra Addons FOR Contact Form 7AI26/9/202628/9/2026
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the…
AplazadaMedia (6.5)0.16%—Contact Form 7AIThemefic Ultimate Addons FOR Contact Form 7AI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.
AplazadaMedia (6.5)0.26%—Advanced Contact Form 7 DBAI23/9/202623/9/2026
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and…
AplazadaMedia (5.8)0.32%—Zealousweb Generate PDF Using Contact Form 7AI18/9/202618/9/2026
The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the server request internal resources and read the response back through the generated PDF.
AplazadaMedia (4.3)0.21%—Advanced Contact Form 7 DBAI10/9/202610/9/2026
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above,…
AplazadaMedia (6.5)0.31%—Contact Form 7 CaptchaAI9/9/20269/9/2026
The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
AplazadaMedia (4.8)0.24%—Redirection FOR Contact Form 7AI6/9/20268/9/2026
The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode…
AplazadaAlta (7.1)0.25%—Calculation FOR Contact Form 7AI3/9/20263/9/2026
Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.
AplazadaAlta (8.1)0.54%—Drag AND Drop Multiple File Upload FOR Contact Form 7AI21/8/202626/8/2026
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.
AplazadaBaja (3.5)0.24%—Drag AND Drop Multiple File Upload FOR Contact Form 7AI21/8/202626/8/2026
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.
AplazadaAlta (7.5)0.42%—Contact Form 7AI19/8/202620/8/2026
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
AplazadaAlta (7.5)0.42%—PAY With Contact Form 7AI19/8/202620/8/2026
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
AplazadaMedia (6.5)0.33%—Contact Form 7 Paypal AND Stripe Add-onAI13/8/202614/8/2026
Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.
AplazadaMedia (6.4)0.26%—Ultraaddons Ultra Addons FOR Contact Form 7AI7/8/202612/8/2026
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slider 'data-label' and 'data-separator' attributes in all versions up to, and including, 3.5.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (4.4)0.31%—Contact Form 7 Dynamic Text ExtensionAI5/8/202612/8/2026
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0.5. This is due to insufficient output escaping on form shortcode keys displayed in the admin "Scan Forms for Post Meta and User Data Keys" page. This makes it possible…
AplazadaMedia (6.8)0.39%—Database FOR Contact Form 7 Wpforms Elementor FormsAI4/8/202626/8/2026
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated…
AplazadaAlta (7.1)0.25%—Database FOR Contact Form 7 Wpforms Elementor FormsAI28/7/202628/7/2026
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaAlta (7.1)0.25%—Themefic Ultimate Addons FOR Contact Form 7AI27/7/202628/7/2026
Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
AplazadaAlta (7.1)0.25%—Contact Form 7AI27/7/202628/7/2026
Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
AplazadaMedia (4.7)0.29%—Contact Form 7AI27/7/202627/7/2026
The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.
AplazadaMedia (6.5)0.47%—Contact Form 7 Dynamic Text ExtensionAI22/7/202629/9/2026
The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible…