Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.39%—Gravityexport LiteAI30/9/202630/9/2026
Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.
AplazadaCrítica (9.8)3.9%—Gravityforms Gravity FormsAI19/9/202621/9/2026
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a…
AplazadaCrítica (9.8)1.1%—Multi Uploader FOR Gravity FormsAI17/9/202619/9/2026
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload…
AplazadaBaja (2)0.36%—Creolabs GravityAI14/9/202616/9/2026
A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of the file src/compiler/gravity_parser.c of the component Number Parser. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The exploit is now…
AplazadaMedia (5.5)0.64%—Creolabs GravityAI14/9/202614/9/2026
A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the file src/utils/gravity_json.c of the component udp json-parser. Such manipulation leads to integer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may…
AplazadaBaja (2.1)0.47%—Creolabs GravityAI14/9/202615/9/2026
A weakness has been identified in marcobambini Gravity up to 0.9.7. The impacted element is an unknown function of the file src/utils/gravity_json.c of the component JSON parser. This manipulation causes memory corruption. The attack is possible to be carried out remotely. The exploit has been made available to the…
AplazadaAlta (7.2)0.51%—Repeater Fields FOR Gravity FormsAI9/9/20269/9/2026
The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaAlta (7.2)0.19%—Gravityforms Gravity FormsAI5/9/20268/9/2026
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…
AplazadaAlta (8.1)0.50%—Gravityforms Gravity FormsAI1/9/20261/9/2026
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in the `GFAsyncUpload::upload()` function, where public form state URL hashes can be reused as chunk continuation hashes and…
AplazadaMedia (5.4)0.23%—Gravity BoosterAI18/8/202620/8/2026
Subscriber Broken Access Control in Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms <= 6.0 versions.
AplazadaAlta (8.5)0.36%—Gravityforms BookingsAI18/8/202620/8/2026
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
AplazadaMedia (4.4)0.33%—Gravity BoosterAI16/8/202620/8/2026
The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level…
AplazadaCrítica (9.1)0.66%—Gravity Forms Multi Uploader Multi Uploader FOR Gravity FormsAI5/8/202612/8/2026
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via `wp_ajax_nopriv_gfmu_delete_file`. The nonce…
AplazadaAlta (7.5)0.93%—Gravityforms Gravity FormsAI15/7/202615/7/2026
The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive…
AplazadaAlta (7.6)0.38%—Hannan Persian Gravity FormsAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through <= 3.0.2.
AplazadaMedia (5.3)0.31%—Gravityplugins GravityviewAI26/6/202626/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.
AplazadaMedia (6.5)0.40%—Gravityforms BookingAI25/6/202625/6/2026
The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaCrítica (9.6)0.50%—Rocketgenius INC Gravity FormsAI1/6/202622/7/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a through 2.10.0.1.
AplazadaAlta (7.5)0.34%—Gravity Bookings PremiumAI6/5/202617/6/2026
The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append…
AplazadaAlta (7.2)0.31%—Gravityforms Gravity FormsAI2/5/202617/6/2026
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.10.0. This is due to a flawed state validation mechanism that fails open when input is sanitized by wp_kses(), combined with insufficient output escaping. The state…
AplazadaAlta (7.2)0.30%—Gravityforms Gravity FormsAI2/5/202617/6/2026
The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names when rendered inside Repeater fields. The validate() method in the…
AplazadaAlta (7.2)0.33%—Rocketgenius Gravity FormsAI2/5/202617/6/2026
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fields, where repeater subfields bypass state validation checks and the…
AplazadaAlta (7.2)0.32%—Gravityforms Gravity FormsAI2/5/202617/6/2026
The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a Repeater field. When SingleProduct fields are nested within Repeater…
AplazadaAlta (7.2)0.30%—Gravityforms Gravity FormsAI2/5/202617/6/2026
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because the state validation function accepts submitted values where the…
AplazadaCrítica (9.3)0.88%—Creolabs GravityAI16/4/202614/7/2026
Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bounds memory by crafting scripts with many string literals at global scope. Attackers can exploit insufficient bounds checking in gravity_fiber_reassign() to corrupt heap…