Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.36% | — | Codepeople CP Contact Form With PaypalAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-contact-form-with-paypal allows Blind SQL Injection.This issue affects CP Contact Form with Paypal: from n/a through <= 1.3.61. | |
| Aplazada | Alta (7.5) | 0.36% | — | CP Contact Form With PaypalAI | 22/11/2025 | 17/6/2026 | The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.56. This is due to the plugin exposing an unauthenticated IPN-like endpoint (via the 'cp_contactformpp_ipncheck' query parameter) that processes payment confirmations without any… | |
| Analizada | Media (6.5) | 0.27% | — | Dwbooster CP Contact Form | 30/1/2025 | 17/6/2026 | The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This is due to missing or incorrect nonce validation on the cp_contact_form_paypal_check_init_actions() function. This makes it possible for unauthenticated attackers to add… | |
| Aplazada | Alta (7.5) | 0.79% | — | Webcodin WCP Contact FormAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0. | |
| Aplazada | Media (4.3) | 0.51% | — | Webcodin WCP Contact FormAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0. | |
| Analizada | Alta (8.8) | 0.38% | — | Codepeople CP Contact Form With Paypal | 3/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople, paypaldev CP Contact Form with Paypal allows Functionality Misuse.This issue affects CP Contact Form with Paypal: from n/a through 1.3.34. | |
| Modificada | Media (6.1) | 0.38% | — | Webcodin WCP Contact Form | 15/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webcodin WCP Contact Form plugin <= 3.1.0 versions. | |
| Modificada | Media (6.1) | 0.94% | — | Codepeople CP Contact Form With Paypal | 15/8/2019 | 17/6/2026 | The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition. | |
| Modificada | Media (5.4) | 0.80% | — | Codepeople CP Contact Form With Paypal | 9/8/2019 | 17/6/2026 | The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter. | |
| Modificada | Alta (7.2) | 2.0% | — | Cfpaypal CP Contact Form With Paypal | 30/9/2017 | 17/6/2026 | The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has SQL injection via the cp_contactformpp_id parameter to cp_contactformpp.php. | |
| Modificada | Alta (8.8) | 1.0% | — | Codepeople CP Contact Form With Paypal | 30/9/2017 | 17/6/2026 | The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php. |