Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2557▼ 320 respecto a la semana anterior
Críticas / altas1342▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.52% | — | Ninjaforms Ninja Forms File UploadsAI | 2/10/2026 | 2/10/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used… | |
| Aplazada | Crítica (9.3) | 0.24% | — | Wordpress File UploadAI | 1/10/2026 | 1/10/2026 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions. | |
| Aplazada | Crítica (9.8) | 1.0% | — | Drag AND Drop File Upload FOR Elementor FormsAI | 10/9/2026 | 10/9/2026 | The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled… | |
| Aplazada | Alta (7.1) | 0.25% | — | Ninjaforms File Uploads ExtensionAI | 3/9/2026 | 5/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| Aplazada | Alta (8.1) | 0.54% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 21/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server. | |
| Aplazada | Baja (3.5) | 0.24% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 21/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field. | |
| Aplazada | Alta (8.6) | 0.45% | — | Iptanus File UploadAI | 9/8/2026 | 26/8/2026 | The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wordpress File UploadAI | 6/8/2026 | 12/8/2026 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. | |
| Aplazada | Crítica (9.1) | 0.49% | — | Codedropz Drag AND Drop Multiple File Upload FOR WoocommerceAI | 6/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy… | |
| Aplazada | Crítica (9.6) | 0.20% | — | Ninjaforms File Uploads ExtensionAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| Aplazada | Media (5.3) | 0.35% | — | Ninjaforms Ninja Forms File UploadsAI | 3/7/2026 | 6/7/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read all plugin debug log… | |
| Aplazada | Alta (7.5) | 0.60% | — | Ninjaforms Ninja Forms File UploadsAI | 2/7/2026 | 2/7/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and including, 3.3.29. This is due to the get_files_for_attachment() function accepting a raw attacker-controlled 'files' array when the process() method returns early due to a… | |
| Aplazada | Alta (7.1) | 0.25% | — | Contact Form 7 Drag AND Drop Multiple File UploadAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.7 versions. | |
| Aplazada | Media (5.4) | 0.16% | — | Iptanus File UploadAI | 14/6/2026 | 23/7/2026 | The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file write operation, an authenticated attacker… | |
| Aplazada | Media (4.4) | 0.34% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 6/6/2026 | 23/7/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings in all versions up to, and including, 1.3.9.7 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Alta (8.1) | 1.1% | — | Drag AND Drop File Upload FOR Contact Form 7AI | 24/4/2026 | 17/6/2026 | The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file extension before sanitization occurs and allowing the file type parameter to be controlled by the attacker rather than… | |
| Aplazada | Alta (8.1) | 3.5% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 17/4/2026 | 17/6/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces the default dangerous extension… | |
| Aplazada | Alta (7.5) | 0.59% | — | WP Drag AND Drop File UploadAI | 17/4/2026 | 17/6/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] POST values as the source of truth for email attachment selection without… | |
| Aplazada | Crítica (9.8) | 63% | — | Ninjaforms Ninja Forms File UploadsAI | 7/4/2026 | 17/6/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to upload arbitrary files on… | |
| Aplazada | Alta (7.5) | 0.43% | — | Snowray Software File Uploader FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce allows Path Traversal.This issue affects File Uploader for WooCommerce: from n/a through <= 1.0.4. | |
| Aplazada | Media (6.8) | 0.35% | — | Add-ons.org Products-file-upload-for-woocommerceAI | 25/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Product File Upload for WooCommerce products-file-upload-for-woocommerce allows Path Traversal.This issue affects Product File Upload for WooCommerce: from n/a through <= 2.2.4. | |
| Aplazada | Alta (8.1) | 0.95% | — | Drag AND Drop Multiple File Upload Contact Form 7AI | 5/3/2026 | 17/6/2026 | The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for unauthenticated attackers to upload arbitrary files… | |
| Aplazada | Media (5.3) | 0.22% | — | Imaginate-solutions File Uploads Addon FOR WoocommerceAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Imaginate Solutions File Uploads Addon for WooCommerce woo-addon-uploads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects File Uploads Addon for WooCommerce: from n/a through <= 1.7.3. | |
| Aplazada | Media (6.1) | 0.37% | — | Drag AND Drop Multiple File Upload Contact Form 7AI | 7/1/2026 | 30/9/2026 | The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files with a dangerous type in all versions up to, and including, 1.3.9.2. This is due to the plugin not blocking .phar and .svg files. This makes it possible for unauthenticated attackers to upload… |