Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2554▼ 405 respecto a la semana anterior
Críticas / altas1317▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.46%—Fluentcrm PROAI27/8/202628/8/2026
Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
AplazadaMedia (4.9)0.19%—Fluentcrm PROAI24/8/202624/8/2026
Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
AplazadaAlta (7.6)0.38%—Fluentcrm Fluent CRM PROAI24/8/202624/8/2026
Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
AplazadaAlta (7.2)0.53%—Fluentcrm Fluent FormsAI29/7/202630/7/2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it…
AplazadaMedia (5.4)0.30%—Fluentcrm Fluent FormsAI10/7/202610/7/2026
The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX flow. This makes it possible for authenticated attackers, with…
AplazadaBaja (3.1)0.21%—Fluentcrm Fluent FormsAI1/7/20261/7/2026
The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users.
AplazadaMedia (5.4)0.83%—Fluentcrm Fluent-crmAI22/5/202623/7/2026
The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.9.87 via the 'SubscribeURL' parameter. This makes it possible for unauthenticated attackers to…
AplazadaMedia (5.3)0.22%—Fluentcrm Fluent FormsAI7/1/202617/6/2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the `fluentform_ai_create_form` AJAX action. This makes it possible for…
AplazadaMedia (6.4)0.29%—Wpmanageninja FluentcrmAI21/11/202517/6/2026
The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fluentcrm_content' shortcode in all versions up to, and including, 2.9.84 due to insufficient input sanitization and output…
ModificadaMedia (4.8)0.36%—Wpmanageninja Fluentcrm29/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Email Newsletter Team - FluentCRM Fluent CRM allows Stored XSS.This issue affects Fluent CRM: from n/a through 2.8.44.
ModificadaBaja (3.7)0.80%—Wpmanageninja Fluentcrm9/6/202317/6/2026
The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 2.8.01 due to the use of an MD5 hash without a salt to control subscriptions. This makes it possible for unauthenticated attackers to unsubscribe users from lists…