Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.29% | — | Kaliforms Kali FormsAI | 27/8/2026 | 28/8/2026 | Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions. | |
| Aplazada | Alta (8.1) | 1.2% | — | Kaliforms Kali FormsAI | 1/8/2026 | 12/8/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder,… | |
| Aplazada | Alta (7.2) | 0.43% | — | Kaliforms Kali FormsAI | 17/7/2026 | 17/7/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.5) | 0.32% | — | Kaliforms Kali FormsAI | 15/7/2026 | 15/7/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type, or status) into a published post they own… | |
| Aplazada | Media (6.4) | 0.42% | — | Kaliforms Kali FormsAI | 1/7/2026 | 1/7/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.8) | 4.4% | — | Kaliforms Kali FormsAI | 20/3/2026 | 17/6/2026 | The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder storage, combined with the use of 'call_user_func' on… | |
| Aplazada | Media (4.3) | 0.30% | — | Kaliforms Kali FormsAI | 18/2/2026 | 17/6/2026 | The Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.8. This is due to the `get_items_permissions_check()` permission callback on the `/kaliforms/v1/forms/{id}` REST API endpoint only checking for the `edit_posts` capability without verifying… | |
| Analizada | Media (5.9) | 0.25% | — | Kaliforms Kali Forms | 16/5/2025 | 17/6/2026 | The Contact Form builder with drag & drop for WordPress WordPress plugin before 2.4.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (5.3) | 0.35% | — | Wpchill Kali FormsAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Chill Kali Forms kali-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kali Forms: from n/a through <= 2.3.27. | |
| Aplazada | Media (6.5) | 0.46% | — | Wpchill Kali FormsAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Chill Kali Forms kali-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kali Forms: from n/a through <= 2.3.28. | |
| Modificada | Alta (8.1) | 0.45% | — | Kaliforms Kali Forms | 31/1/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress – Kali Forms: from n/a through 2.3.36. | |
| Modificada | Alta (7.1) | 0.79% | — | Kaliforms Kali Forms | 7/6/2023 | 17/6/2026 | The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the plugin's settings. | |
| Modificada | Alta (8.8) | 0.48% | — | Kaliforms Kali Forms | 7/6/2023 | 17/6/2026 | The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plugin's function. This makes it possible for unauthenticated attackers to access the plugin's administrative functions via forged request… | |
| Modificada | Media (5.3) | 0.73% | — | Kaliforms Kali Forms | 7/6/2023 | 17/6/2026 | The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This makes it possible for unauthenticated attackers to delete any site post… |