Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.21% | — | Wordpress Contact Form BuilderAI | 10/5/2026 | 24/7/2026 | WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary… | |
| Aplazada | Alta (7.2) | 0.24% | — | Responsive Contact Form BuilderAI | 11/3/2026 | 17/6/2026 | The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 via form field submissions. This is due to insufficient input sanitization in the lfb_lead_sanitize() function which omits certain field types from… | |
| Modificada | Media (4.8) | 0.23% | — | Vikasratudi Lifetime Free Drag & Drop Contact Form Builder | 22/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VPSUForm v-form allows Stored XSS.This issue affects VPSUForm: from n/a through <= 3.1.14. | |
| Aplazada | Media (6.5) | 0.27% | — | Vcita Contact Form BuilderAI | 10/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyale-vc Contact Form Builder by vcita contact-form-with-a-meeting-scheduler-by-vcita allows DOM-Based XSS.This issue affects Contact Form Builder by vcita: from n/a through <= 4.10.2. | |
| Analizada | Media (6.5) | 0.40% | — | Bitapps Contact Form Builder | 25/1/2025 | 17/6/2026 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.17.4 via the Webhooks integration. This makes it possible for authenticated attackers,… | |
| Modificada | Crítica (9.8) | 0.62% | — | Wpmet Metform Elementor Contact Form Builder | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Roxnor Metform metform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Metform: from n/a through <= 3.4.0. | |
| Aplazada | Media (6.4) | 0.33% | — | Vcita Contact Form BuilderAI | 5/12/2024 | 17/6/2026 | The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's livesite-pay shortcode in all versions up to, and including, 4.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (6.5) | 0.92% | — | Bitapps Contact Form Builder | 20/8/2024 | 17/6/2026 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the iconRemove function in versions 2.0 to 2.13.4. This makes it possible for… | |
| Analizada | Alta (7.2) | 0.51% | — | Bitapps Contact Form Builder | 20/8/2024 | 17/6/2026 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the id parameter in versions 2.0 to 2.13.9 due to insufficient escaping on the user-supplied parameter and lack of sufficient… | |
| Analizada | Crítica (9) | 1.0% | — | Bitapps Contact Form Builder | 20/8/2024 | 17/6/2026 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in multiple functions in versions 2.0 to 2.13.9. This makes it possible for… | |
| Analizada | Media (4.8) | 0.26% | — | Bitapps Contact Form Builder | 20/8/2024 | 17/6/2026 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing input validation in the addCustomCode function in versions 2.0 to 2.13.9. This makes it possible for… | |
| Analizada | Alta (7.2) | 0.45% | — | Bitapps Contact Form Builder | 20/8/2024 | 17/6/2026 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the entryID parameter in versions 2.0 to 2.13.9 due to insufficient escaping on the user-supplied parameter and lack of sufficient… | |
| Analizada | Crítica (9.8) | 0.96% | — | Wpmet Metform Elementor Contact Form Builder | 17/8/2024 | 17/6/2026 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in versions up to, and including, 3.2.4. This allows unauthenticated visitors to perform a "double extension" attack and upload files containing a malicious extension but ending with… | |
| Modificada | Alta (7.5) | 0.55% | — | Wpmet Metform Elementor Contact Form Builder | 11/6/2024 | 17/6/2026 | The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function. This can allow unauthenticated attackers to extract sensitive data, such as Personally Identifiable… | |
| Modificada | Media (5.3) | 0.37% | — | Contact Form Builder Project Contact Form Builder | 10/6/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in wpdevart Contact Form Builder, Contact Widget allows Functionality Bypass.This issue affects Contact Form Builder, Contact Widget: from n/a through 2.1.7. | |
| Aplazada | Media (5.4) | 0.33% | — | Responsive Contact Form Builder Lead Generation PluginAI | 22/5/2024 | 17/6/2026 | The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes… | |
| Modificada | Alta (8.8) | 0.44% | — | Wpmet Metform Elementor Contact Form Builder | 6/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Roxnor Metform metform.This issue affects Metform: from n/a through <= 3.8.3. | |
| Aplazada | Media (4.3) | 0.27% | — | Responsive Contact Form Builder Lead Generation PluginAI | 2/5/2024 | 17/6/2026 | The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on several functions in all versions up to, and including, 1.8.9. This makes it possible for unauthenticated attackers to invoke those functions. | |
| Aplazada | Media (4.3) | 0.27% | — | Responsive Contact Form Builder Lead Generation PluginAI | 2/5/2024 | 17/6/2026 | The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.9. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those… | |
| Modificada | Media (5.4) | 0.32% | — | Wpmet Metform Elementor Contact Form Builder | 2/4/2024 | 17/6/2026 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 3.8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Media (5.3) | 0.48% | — | Bitapps Contact Form Builder | 13/3/2024 | 17/6/2026 | The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient user validation on the bitforms_update_form_entry AJAX action in all versions up to, and including, 2.10.1. This… | |
| Modificada | Media (5.4) | 0.50% | — | Wpmet Metform Elementor Contact Form Builder | 13/3/2024 | 17/6/2026 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.31% | — | Kaliforms Contact Form Builder | 29/2/2024 | 17/6/2026 | The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in all versions up to, and including, 2.3.41. This makes it possible for authenticated… | |
| Modificada | Media (4.3) | 0.31% | — | Kaliforms Contact Form Builder | 29/2/2024 | 17/6/2026 | The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.23% | — | Wpmet Metform Elementor Contact Form Builder | 9/1/2024 | 17/6/2026 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.1. This is due to missing or incorrect nonce validation on the contents function. This makes it possible for unauthenticated attackers to update the options… |