Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2819▲ 31 respecto a la semana anterior
Críticas / altas1469▲ 254 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.27% | — | Jet-form-builder-stripe-gatewayAI | 23/9/2026 | 23/9/2026 | The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes. | |
| Aplazada | Media (5.3) | 0.30% | — | Whitestudio Easy Form BuilderAI | 18/9/2026 | 18/9/2026 | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress accounts on a site whose owner has disabled registration. | |
| Aplazada | Alta (8.8) | 0.51% | — | Whitestudio Easy Form BuilderAI | 18/9/2026 | 18/9/2026 | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS. | |
| Aplazada | Alta (7.5) | 0.32% | — | Jetformbuilder Dynamic Blocks Form BuilderAI | 5/9/2026 | 8/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft… | |
| Aplazada | Alta (7.1) | 0.25% | — | Whitestudio Easy Form BuilderAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. | |
| Aplazada | Crítica (9.8) | 0.71% | — | Whitestudio Easy Form BuilderAI | 21/7/2026 | 21/7/2026 | The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in… | |
| Aplazada | Alta (7.5) | 0.47% | — | Sureforms Drag AND Drop Form BuilderAI | 10/7/2026 | 14/7/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 2.2.1. This is due to the plugin accepting the payment amount directly from user-controlled POST data in the 'create_payment_intent' and… | |
| Aplazada | Alta (8.8) | 0.44% | — | Elegantthemes Divi Form BuilderAI | 9/7/2026 | 9/7/2026 | The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and… | |
| Aplazada | Crítica (9.8) | 3.5% | — | Divi Form BuilderAI | 2/7/2026 | 2/7/2026 | The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is… | |
| Aplazada | Media (5.4) | 0.27% | — | Codepeople Form Builder CPAI | 15/6/2026 | 21/7/2026 | The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script execution, allowing authenticated users with Editor-level access and above to perform Stored Cross-Site Scripting attacks against any visitor of a page… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Whitestudio Easy Form BuilderAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder: from n/a through <= 4.0.6. | |
| Aplazada | Alta (7.1) | 0.21% | — | Wordpress Ultimate Form Builder LiteAI | 23/5/2026 | 23/7/2026 | WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the entry_id POST parameter. Attackers can send POST requests to the admin-ajax.php endpoint with the… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Divi Form BuilderAI | 21/5/2026 | 23/7/2026 | The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's configured default_user_role setting. This… | |
| Aplazada | Media (5.1) | 0.21% | — | Wordpress Contact Form BuilderAI | 10/5/2026 | 24/7/2026 | WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary… | |
| Aplazada | Media (5.3) | 0.39% | — | Eshot Form BuilderAI | 15/4/2026 | 17/6/2026 | The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.2. The eshot_form_builder_update_field_data() AJAX handler lacks any capability checks (current_user_can()) or nonce verification (check_ajax_referer()/wp_verify_nonce()). The function is… | |
| Aplazada | Media (5.3) | 0.40% | — | Eshot Form BuilderAI | 21/3/2026 | 17/6/2026 | The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.2. The eshot_form_builder_get_account_data() function is registered as a wp_ajax_ AJAX handler accessible to all authenticated users. The function lacks any capability check (e.g.,… | |
| Aplazada | Alta (7.2) | 0.24% | — | Responsive Contact Form BuilderAI | 11/3/2026 | 17/6/2026 | The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 via form field submissions. This is due to insufficient input sanitization in the lfb_lead_sanitize() function which omits certain field types from… | |
| Aplazada | Media (5.3) | 0.24% | — | Whitestudio Easy Form BuilderAI | 14/2/2026 | 17/6/2026 | The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive form response… | |
| Analizada | Media (4.8) | 0.24% | — | Silence Form Builder | 28/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Form Builder allows Cross-Site Scripting (XSS).This issue affects Drupal: from 7.X-1.0 through 7.X-1.22. | |
| Aplazada | Media (4.3) | 0.14% | — | Surveyjs Drag Drop Wordpress Form BuilderAI | 24/1/2026 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the `SurveyJS_CloneSurvey` AJAX action. This… | |
| Aplazada | Media (4.3) | 0.15% | — | Surveyjs Drag Drop Wordpress Form BuilderAI | 24/1/2026 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce verification on the 'SurveyJS_RenameSurvey' AJAX action. This makes it… | |
| Aplazada | Media (4.3) | 0.15% | — | Surveyjs Drag AND Drop Form BuilderAI | 24/1/2026 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce validation on the SurveyJS_AddSurvey AJAX action. This makes it possible for unauthenticated attackers to create surveys via a… | |
| Aplazada | Media (4.3) | 0.21% | — | Whitestudio Easy Form BuilderAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <= 3.9.6. | |
| Aplazada | Media (6.4) | 0.28% | — | Stylish Order Form BuilderAI | 7/1/2026 | 17/6/2026 | The Stylish Order Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'product_name' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (5.3) | 0.25% | — | Whitestudio Easy Form BuilderAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <= 3.8.20. |