Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 436 respecto a la semana anterior
Críticas / altas1431▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 168 respecto a la semana anterior
1170 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | — | — | Super-forms Super FormsAI | 1/10/2026 | 1/10/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super… | |
| Aplazada | Crítica (9.8) | — | — | Super-forms Super FormsAI | 1/10/2026 | 1/10/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that… | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | Kiteworks Secure Data FormsAI | 30/9/2026 | 1/10/2026 | A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an… | |
| Pendiente de análisis | Alta (7.5) | 0.45% | — | Kiteworks Secure Data FormsAI | 30/9/2026 | 1/10/2026 | Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other… | |
| Pendiente de análisis | Alta (7.2) | 0.35% | — | Kiteworks Advanced FormsAI | 30/9/2026 | 1/10/2026 | A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions. | |
| Pendiente de análisis | Baja (1.2) | 0.40% | — | Wikimedia Page FormsAI | 30/9/2026 | 30/9/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43. | |
| Aplazada | Alta (7.1) | 0.25% | — | HappyformsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions. | |
| Aplazada | Alta (8.8) | 0.52% | — | Quantumcloud Conversational Forms FOR ChatbotAI | 30/9/2026 | 30/9/2026 | Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Ninjaforms Ninja FormsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | |
| Pendiente de análisis | Crítica (9.5) | 0.32% | — | Balbooa FormsAI | 29/9/2026 | 30/9/2026 | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component… | |
| Pendiente de análisis | Alta (8.9) | 0.37% | — | Balbooa FormsAI | 29/9/2026 | 30/9/2026 | Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the… | |
| Pendiente de análisis | Alta (8.6) | 0.32% | — | Balbooa FormsAI | 29/9/2026 | 30/9/2026 | Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A… | |
| Pendiente de análisis | Media (6.9) | 0.37% | — | Balbooa FormsAI | 29/9/2026 | 30/9/2026 | Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and display names are trusted directly, introducing potential cross-session claiming, metadata… | |
| Pendiente de análisis | Media (6.9) | 0.29% | — | Balbooa FormsAI | 29/9/2026 | 30/9/2026 | Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session… | |
| Aplazada | Media (6.5) | 0.18% | — | Wpforms LiteAI | 28/9/2026 | 28/9/2026 | The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public… | |
| Aplazada | Alta (7.2) | 0.24% | — | Repeater Fields FOR Elementor FormsAI | 25/9/2026 | 25/9/2026 | The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (6.1) | 0.27% | — | WpformsAI | 25/9/2026 | 25/9/2026 | The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'page_title' POST Parameter via {page_title} Smart Tag in all versions up to, and including, 2.0.2 due to insufficient input sanitization and… | |
| Aplazada | Media (6.8) | 0.18% | — | WpformsAI | 24/9/2026 | 24/9/2026 | The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate subscription cancellation against payments created by other applications on the… | |
| Aplazada | Alta (7.1) | 0.18% | — | Ninjaforms Ninja FormsAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | |
| Aplazada | Alta (8.5) | 0.22% | — | Mollie FormsAI | 23/9/2026 | 23/9/2026 | Contributor SQL Injection in Mollie Forms <= 2.11.0 versions. | |
| Aplazada | Media (6.8) | 0.24% | — | Subscribe FormsAI | 23/9/2026 | 23/9/2026 | The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who views a page embedding the… | |
| Aplazada | Baja (3.7) | 0.15% | — | Wpmudev Forminator FormsAI | 23/9/2026 | 23/9/2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail… | |
| Pendiente de análisis | Crítica (9.6) | 0.73% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 23/9/2026 | Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope… | |
| Pendiente de análisis | Alta (8.7) | 0.81% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 23/9/2026 | Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction.… | |
| Pendiente de análisis | Crítica (9.1) | 1.2% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 23/9/2026 | Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user… |