Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.19% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions. | |
| Aplazada | Media (6.5) | 0.13% | — | FluentformAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP ManageNinja LLC FluentForm fluentform allows Stored XSS.This issue affects FluentForm: from n/a through 6.2.14. | |
| Aplazada | Media (5.3) | 0.19% | — | FluentformAI | 1/10/2026 | 1/10/2026 | Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14. | |
| Aplazada | Alta (7.5) | 0.32% | — | Fluentforms Fluent Forms PROAI | 31/8/2026 | 1/9/2026 | Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 31/8/2026 | 1/9/2026 | Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. | |
| Aplazada | Alta (7.2) | 0.49% | — | Fluentform Fluent FormsAI | 13/8/2026 | 14/8/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode Values in all versions up to, and including, 6.2.11 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.1) | 0.37% | — | Fluentforms Fluent FormsAI | 1/8/2026 | 12/8/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'param' in all versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.63% | — | Fluentforms Fluent FormsAI | 31/7/2026 | 12/8/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.25% | — | Fluentforms Fluent FormsAI | 30/7/2026 | 30/7/2026 | The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the… | |
| Aplazada | Baja (2.7) | 0.28% | — | Fluentforms Fluent FormsAI | 2/7/2026 | 2/7/2026 | The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage, allowing a Manager limited to specific forms to permanently delete submission entries belonging to other forms. This requires a non-default… | |
| Aplazada | Alta (8.2) | 0.38% | — | Fluentforms Fluent FormsAI | 14/5/2026 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Alta (8.2) | 0.37% | — | Fluentforms Fluent FormsAI | 14/5/2026 | 17/6/2026 | The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21. This is due to the SubmissionPolicy class authorizing submission-level actions (read, modify, delete, add notes) based on a user-supplied `form_id` query parameter. This… | |
| Aplazada | Media (6.4) | 0.35% | — | Fluentforms Fluent FormsAI | 13/5/2026 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permission_message' parameter in all versions up to, and including, 6.2.1 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (4.9) | 0.83% | — | Fluentforms Fluent FormsAI | 6/5/2026 | 17/6/2026 | The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNotificationActions, which resolves attacker-supplied file-upload URLs into filesystem paths without verifying that the… | |
| Aplazada | Media (5.3) | 0.31% | — | Fluentforms Fluent FormsAI | 16/4/2026 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and ownership validation on a user… | |
| Aplazada | Media (6.5) | 0.37% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 5/3/2026 | 17/6/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.17. This is due to the `deleteFile()` method in the `Uploader` class lacking nonce verification and capability checks. The AJAX action is registered via `addPublicAjaxAction()` which… | |
| Aplazada | Alta (7.2) | 0.27% | — | Fluentforms Fluent Forms PROAI | 5/3/2026 | 17/6/2026 | The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_save_data` AJAX action in all versions up to, and including, 6.1.17. This is due to the draft form submission endpoint being publicly accessible without authentication or nonce verification, combined… | |
| Aplazada | Alta (7.5) | 0.14% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 27/2/2026 | 17/6/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (`disable_ipn_verification` defaults to `'yes'` in… | |
| Aplazada | Media (4.3) | 0.19% | — | FluentformAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Shahjahan Jewel FluentForm fluentform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentForm: from n/a through <= 6.1.14. | |
| Aplazada | Media (6.4) | 0.29% | — | Fluentforms Fluent FormsAI | 10/2/2026 | 17/6/2026 | The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all versions up to, and including, 6.1.14 due to a combination of missing authorization checks, a leaked nonce, and insufficient input sanitization. The vulnerability allows Subscriber-level users to… | |
| Aplazada | Media (5.4) | 0.24% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 9/2/2026 | 17/6/2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations… | |
| Aplazada | Media (5.3) | 0.27% | — | Shahjahan Jewel FluentformAI | 22/1/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Shahjahan Jewel FluentForm fluentform allows Code Injection.This issue affects FluentForm: from n/a through <= 6.1.11. | |
| Aplazada | Media (5.3) | 0.28% | — | Fluentforms Fluent FormsAI | 6/12/2025 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.1.7 via the 'submission_id' parameter due to missing validation on a user controlled key within the… | |
| Aplazada | Media (6.5) | 0.58% | — | Fluentforms Fluent FormsAI | 3/9/2025 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 to 6.1.1 via deserialization of untrusted input in the parseUserProperties function. This makes it possible for authenticated attackers, with… |