Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.32% | — | Fluentforms Fluent Forms PROAI | 31/8/2026 | 1/9/2026 | Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 31/8/2026 | 1/9/2026 | Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. | |
| Aplazada | Crítica (9.3) | 0.67% | — | Fluent Forms PROAI | 13/8/2026 | 9/9/2026 | Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a… | |
| Aplazada | Alta (7.2) | 0.49% | — | Fluentform Fluent FormsAI | 13/8/2026 | 14/8/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode Values in all versions up to, and including, 6.2.11 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.1) | 0.37% | — | Fluentforms Fluent FormsAI | 1/8/2026 | 12/8/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'param' in all versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.63% | — | Fluentforms Fluent FormsAI | 31/7/2026 | 12/8/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.25% | — | Fluentforms Fluent FormsAI | 30/7/2026 | 30/7/2026 | The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the… | |
| Aplazada | Alta (7.2) | 0.53% | — | Fluentcrm Fluent FormsAI | 29/7/2026 | 30/7/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Alta (8.8) | 0.55% | — | Fluent Forms PRO ADD ON PackAI | 26/7/2026 | 27/7/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of… | |
| Aplazada | Media (5.4) | 0.30% | — | Fluentcrm Fluent FormsAI | 10/7/2026 | 10/7/2026 | The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX flow. This makes it possible for authenticated attackers, with… | |
| Aplazada | Baja (2.7) | 0.28% | — | Fluentforms Fluent FormsAI | 2/7/2026 | 2/7/2026 | The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage, allowing a Manager limited to specific forms to permanently delete submission entries belonging to other forms. This requires a non-default… | |
| Aplazada | Baja (3.1) | 0.21% | — | Fluentcrm Fluent FormsAI | 1/7/2026 | 1/7/2026 | The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users. | |
| Aplazada | Alta (8.2) | 0.38% | — | Fluentforms Fluent FormsAI | 14/5/2026 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Alta (8.2) | 0.37% | — | Fluentforms Fluent FormsAI | 14/5/2026 | 17/6/2026 | The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21. This is due to the SubmissionPolicy class authorizing submission-level actions (read, modify, delete, add notes) based on a user-supplied `form_id` query parameter. This… | |
| Aplazada | Media (6.4) | 0.35% | — | Fluentforms Fluent FormsAI | 13/5/2026 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permission_message' parameter in all versions up to, and including, 6.2.1 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (4.9) | 0.83% | — | Fluentforms Fluent FormsAI | 6/5/2026 | 17/6/2026 | The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNotificationActions, which resolves attacker-supplied file-upload URLs into filesystem paths without verifying that the… | |
| Aplazada | Media (5.3) | 0.31% | — | Fluentforms Fluent FormsAI | 16/4/2026 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and ownership validation on a user… | |
| Aplazada | Media (6.5) | 0.37% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 5/3/2026 | 17/6/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.17. This is due to the `deleteFile()` method in the `Uploader` class lacking nonce verification and capability checks. The AJAX action is registered via `addPublicAjaxAction()` which… | |
| Aplazada | Alta (7.2) | 0.27% | — | Fluentforms Fluent Forms PROAI | 5/3/2026 | 17/6/2026 | The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_save_data` AJAX action in all versions up to, and including, 6.1.17. This is due to the draft form submission endpoint being publicly accessible without authentication or nonce verification, combined… | |
| Aplazada | Alta (7.5) | 0.14% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 27/2/2026 | 17/6/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (`disable_ipn_verification` defaults to `'yes'` in… | |
| Aplazada | Media (6.4) | 0.29% | — | Fluentforms Fluent FormsAI | 10/2/2026 | 17/6/2026 | The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all versions up to, and including, 6.1.14 due to a combination of missing authorization checks, a leaked nonce, and insufficient input sanitization. The vulnerability allows Subscriber-level users to… | |
| Aplazada | Media (5.4) | 0.24% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 9/2/2026 | 17/6/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations… | |
| Aplazada | Media (5.3) | 0.21% | — | Fluentcrm Fluent FormsAI | 7/1/2026 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the `fluentform_ai_create_form` AJAX action. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.28% | — | Fluentforms Fluent FormsAI | 6/12/2025 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.1.7 via the 'submission_id' parameter due to missing validation on a user controlled key within the… |