Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.33% | — | Codepeople Contact Form EmailAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.63. | |
| Modificada | Media (4.8) | 0.31% | — | Codepeople Contact Form Email | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Contact Form Email contact-form-to-email allows Stored XSS.This issue affects Contact Form Email: from n/a through <= 1.3.52. | |
| Analizada | Media (6.5) | 0.31% | — | Codepeople Contact Form Email | 4/6/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Contact Form Email allows Functionality Bypass.This issue affects Contact Form Email: from n/a through 1.3.41. | |
| Analizada | Media (4.3) | 0.31% | — | Codepeople Contact Form Email | 4/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople Contact Form Email allows Functionality Misuse.This issue affects Contact Form Email: from n/a through 1.3.31. | |
| Modificada | Media (5.3) | 0.47% | — | Codepeople Contact Form Email | 10/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue affects Contact Form Email: from n/a through 1.3.44. | |
| Modificada | Media (4.8) | 0.46% | — | Codepeople Contact Form Email | 11/12/2023 | 17/6/2026 | The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.4) | 0.51% | — | Codepeople Contact Form Email | 12/6/2023 | 17/6/2026 | The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability. | |
| Modificada | Media (4.8) | 0.62% | — | Codepeople Contact Form Email | 17/11/2021 | 17/6/2026 | The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the name parameter found in the ~/trunk/cp-admin-int-list.inc.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to… | |
| Modificada | Alta (8.8) | 0.68% | — | Codepeople Contact Form Email | 13/8/2019 | 17/6/2026 | The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF. | |
| Modificada | Media (6.1) | 0.92% | — | Codepeople Contact Form Email | 13/8/2019 | 17/6/2026 | The contact-form-to-email plugin before 1.2.66 for WordPress has XSS. | |
| Modificada | Media (6.1) | 1.4% | — | Codepeople Contact Form Email | 10/3/2019 | 17/6/2026 | The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area." |