Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.32% | — | Fluentforms Fluent Forms PROAI | 31/8/2026 | 1/9/2026 | Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 31/8/2026 | 1/9/2026 | Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. | |
| Aplazada | Crítica (9.3) | 0.67% | — | Fluent Forms PROAI | 13/8/2026 | 9/9/2026 | Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a… | |
| Aplazada | Alta (8.8) | 0.55% | — | Fluent Forms PRO ADD ON PackAI | 26/7/2026 | 27/7/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of… | |
| Aplazada | Media (6.5) | 0.37% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 5/3/2026 | 17/6/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.17. This is due to the `deleteFile()` method in the `Uploader` class lacking nonce verification and capability checks. The AJAX action is registered via `addPublicAjaxAction()` which… | |
| Aplazada | Alta (7.2) | 0.27% | — | Fluentforms Fluent Forms PROAI | 5/3/2026 | 17/6/2026 | The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_save_data` AJAX action in all versions up to, and including, 6.1.17. This is due to the draft form submission endpoint being publicly accessible without authentication or nonce verification, combined… | |
| Aplazada | Alta (7.5) | 0.14% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 27/2/2026 | 17/6/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (`disable_ipn_verification` defaults to `'yes'` in… | |
| Aplazada | Media (5.4) | 0.24% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 9/2/2026 | 17/6/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations… |