Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 562 respecto a la semana anterior
Críticas / altas1454▲ 281 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.19% | — | Strategy11 Formidable FormsAI | 16/9/2026 | 16/9/2026 | The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing unauthenticated visitors to have arbitrary shortcodes, with attacker-chosen attributes, executed server-side… | |
| Aplazada | Media (4.3) | 0.14% | — | Strategy11 Formidable FormsAI | 16/9/2026 | 17/9/2026 | The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies on that identifier when deciding whether to strip HTML from stored entry values, allowing unauthenticated visitors to have markup rendered in the admin entry view… | |
| Aplazada | Alta (7.5) | 0.69% | — | Formidable ChartsAIFormidable FormsAI | 26/8/2026 | 27/8/2026 | The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Successful… | |
| Aplazada | Alta (7.2) | 0.41% | — | Strategy11 Formidable FormsAI | 26/8/2026 | 26/8/2026 | The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frm_user_id' parameter in all versions up to, and including, 6.33.1 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Crítica (9.8) | 0.67% | — | Formidable Digital SignaturesAI | 11/8/2026 | 12/8/2026 | The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled… | |
| Aplazada | Media (5.9) | 0.18% | — | Strategy11 Formidable FormsAI | 6/8/2026 | 26/8/2026 | The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without… | |
| Aplazada | Alta (7.5) | 0.39% | — | Formidable Forms Signature Online Contract AutomationAI | 6/8/2026 | 12/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. | |
| Aplazada | Media (6.4) | 0.32% | — | Formidable KineticAI | 27/5/2026 | 17/6/2026 | The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'kinetic_link' shortcode in versions up to, and including, 1.1.01. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes (notably 'window', 'class', and 'label') in the… | |
| Aplazada | Alta (7.5) | 0.51% | — | Strategy11 Formidable FormsAI | 13/3/2026 | 17/6/2026 | The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`) marking payment records as complete based solely on the Stripe PaymentIntent status without… | |
| Aplazada | Media (5.3) | 0.44% | — | Strategy11 Formidable FormsAI | 13/3/2026 | 17/6/2026 | The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all versions up to, and including, 6.28. This is due to the `frm_strp_amount` AJAX handler (`update_intent_ajax`) overwriting the global `$_POST` data with attacker-controlled JSON input and then using… | |
| Aplazada | Media (5.3) | 0.31% | — | Integration FOR Salesforce AND Contact Form 7 Wpforms Elementor Formidable Ninja FormsAI | 30/5/2025 | 17/6/2026 | The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used… | |
| Analizada | Baja (3.1) | 0.44% | — | Node-formidable Formidable | 26/4/2025 | 17/6/2026 | Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed,… | |
| Aplazada | Media (4.3) | 0.19% | — | Crmperks WP Zendesk FOR Contact Form 7 Wpforms Elementor Formidable AND Ninja FormsAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-zendesk allows Cross Site Request Forgery.This issue affects WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through <= 1.1.3. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crmperks WP Dynamics CRM FOR Contact Form 7AICrmperks WP Dynamics CRM FOR WpformsAICrmperks WP Dynamics CRM FOR ElementorAICrmperks WP Dynamics CRM FOR FormidableAI+1 | 27/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-dynamics-crm allows Reflected XSS.This issue affects WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable… | |
| Modificada | Crítica (9.8) | 0.52% | — | Strategy11 Formidable Forms | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Formidable Forms: from n/a through 5.5.4. | |
| Analizada | Media (6.1) | 0.40% | — | Strategy11 Formidable Forms | 23/11/2024 | 17/6/2026 | The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insufficient input sanitization and output… | |
| Analizada | Media (4.8) | 0.43% | — | Strategy11 Formidable Forms | 21/11/2024 | 17/6/2026 | The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.5) | 0.23% | — | Wpwebsitecreator WP Website CreatorAIWpformsAIFormidableAINinjaAI+2 | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpwebsitecreator Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera wp-website-creator allows Stored XSS.This issue affects Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera:… | |
| Analizada | Media (5.3) | 1.1% | — | Strategy11 Formidable Form Builder | 16/10/2024 | 17/6/2026 | The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form. | |
| Analizada | Media (6.1) | 1.1% | — | Strategy11 Formidable Form Builder | 16/10/2024 | 17/6/2026 | The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Analizada | Media (5.4) | 0.37% | — | Strategy11 Formidable Forms | 31/7/2024 | 17/6/2026 | The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ parameter in all versions up to, and including, 6.11.1 due to insufficient input sanitization and output escaping. This makes it… | |
| Analizada | Media (6.1) | 0.34% | — | Strategy11 Formidable Forms | 17/5/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affects Formidable Forms: from n/a through 6.7. | |
| Modificada | Media (4.3) | 0.21% | — | Strategy11 Formidable Forms | 5/2/2024 | 17/6/2026 | The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.2. This is due to missing or incorrect nonce validation on the update_settings function. This makes it possible… | |
| Modificada | Alta (7.5) | 0.70% | — | Strategy11 Formidable Forms | 16/1/2024 | 17/6/2026 | The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present. | |
| Modificada | Media (4.8) | 0.31% | — | Strategy11 Formidable Form Builder | 9/1/2024 | 17/6/2026 | The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name field label and description field label parameter in all versions up to 6.7 (inclusive) due to insufficient input sanitization and output… |