Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

64 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.55%—Incsub ForminatorAI1/10/20261/10/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (7.2)0.28%—Incsub ForminatorAI1/10/20261/10/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaMedia (5.3)0.19%—Incsub ForminatorAI23/9/202623/9/2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress reserves for its own use, so unauthenticated visitors submitting a public form that collects post content can attach metadata of their choosing to the post…
AplazadaMedia (5.3)0.12%—Wpmudev ForminatorAI23/9/202623/9/2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwarding headers over the connecting address, and it uses that value both to enforce its per-visitor voting limit and to record who submitted an entry. Unauthenticated…
AplazadaBaja (3.7)0.15%—Wpmudev Forminator FormsAI23/9/202623/9/2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail…
AplazadaBaja (3.1)0.13%—Incsub ForminatorAI23/9/202623/9/2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and that construction happens on every wp-admin request for any logged-in user. Any authenticated user,…
AplazadaMedia (6.6)0.36%—Incsub ForminatorAI20/9/202621/9/2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who…
AplazadaAlta (8.5)0.47%—Wpforms ForminatorAI20/9/202621/9/2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an…
AplazadaCrítica (9.1)0.73%—Incsub ForminatorAI19/9/202621/9/2026
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running…
AplazadaMedia (5.3)0.29%—Incsub ForminatorAI28/8/202628/8/2026
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
AplazadaAlta (7.2)0.45%—Incsub ForminatorAI28/8/202628/8/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaBaja (3.7)0.15%—Incsub ForminatorAI26/8/202626/8/2026
The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress multisite network and gain administrator privileges on it.
AplazadaAlta (7.2)0.35%—Wpmudev ForminatorAI25/8/202626/8/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 1.57.0 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaAlta (7.2)0.44%—Wpmudev ForminatorAI25/8/202626/8/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) in all versions up to, and including, 1.57.0.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.6)0.36%—Wpmudev Forminator FormsAI22/8/202626/8/2026
The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.
AplazadaAlta (7.2)0.66%—Incsub ForminatorAI22/8/202626/8/2026
The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
AplazadaCrítica (9.8)0.56%—Incsub ForminatorAI20/8/202620/8/2026
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
AplazadaCrítica (9.8)6.1%—Incsub ForminatorAI18/8/202620/8/2026
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed…
AplazadaMedia (5.3)0.52%—Wpmudev ForminatorAI16/8/202620/8/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.55.0.2 via the 'draft' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated…
AplazadaAlta (7.1)0.25%—Incsub ForminatorAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
AplazadaAlta (8.8)0.42%—Incsub ForminatorAI6/8/202612/8/2026
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
AplazadaAlta (7.2)0.48%—Wpdesk ForminatorAI6/8/202612/8/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (7.5)0.50%—Wpmudev ForminatorAI13/7/202613/7/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Path Traversal.This issue affects Forminator: from n/a through <= 1.55.0.2.
AplazadaAlta (7.1)0.25%—Wpmudev ForminatorAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows DOM-Based XSS.This issue affects Forminator: from n/a through <= 1.55.0.1.
AplazadaAlta (7.1)0.25%—Incsub ForminatorAI25/6/202625/6/2026
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.