Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.39% | — | Mdmag Quill FormsAI | 19/9/2026 | 21/9/2026 | The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.1) | 0.25% | — | Mdmag Quill FormsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. | |
| Aplazada | Alta (7.2) | 0.32% | — | Mdmag Quill FormsAI | 18/8/2026 | 20/8/2026 | The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Media (5.5) | 0.14% | — | Anchore Quill | 11/3/2026 | 17/6/2026 | Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains an unbounded memory allocation vulnerability when parsing Mach-O binaries. Exploitation requires that Quill processes an attacker-supplied Mach-O binary, which is most likely in environments such as CI/CD… | |
| Analizada | Media (5.3) | 0.12% | — | Anchore Quill | 11/3/2026 | 17/6/2026 | Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded reads of HTTP response bodies during the Apple notarization process. Exploitation requires the ability to modify API responses from Apple's notarization service, which is not possible under standard… | |
| Analizada | Media (5.3) | 0.11% | — | Anchore Quill | 11/3/2026 | 17/6/2026 | Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains a Server-Side Request Forgery (SSRF) vulnerability when attempting to fetch the Apple notarization submission logs. Exploitation requires the ability to modify API responses from Apple's notarization… | |
| Modificada | Media (5.1) | 0.26% | — | Slab Quill | 13/1/2026 | 17/6/2026 | A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This issue affects Quill: 2.0.3. | |
| Analizada | Media (6.4) | 0.27% | — | Mdmag Quill Forms | 7/1/2025 | 17/6/2026 | The Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation Form on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quillforms-popup' shortcode in all versions up to, and including, 3.10.0 due to… | |
| Aplazada | Media (6.5) | 0.37% | — | QuillformsAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Mohamed Magdy Quill Forms quillforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quill Forms: from n/a through <= 3.3.0. | |
| Aplazada | Media (6.5) | 0.25% | — | Mdmag Quill FormsAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mohamed Magdy Quill Forms quillforms allows Stored XSS.This issue affects Quill Forms: from n/a through <= 3.7.0. | |
| Modificada | Media (6.1) | 0.71% | — | Quill-mention Quill Mention | 28/9/2023 | 17/6/2026 | Versions of the package quill-mention before 4.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization, via the renderList function. **Note:** If the mentions list is sourced from unsafe (user-sourced) data, this might allow an injection attack when a Quill user hits @. | |
| Modificada | Media (6.1) | 1.3% | — | Slab Quill | 12/4/2021 | 17/6/2026 | A vulnerability in the HTML editor of Slab Quill 4.8.0 allows an attacker to execute arbitrary JavaScript by storing an XSS payload (a crafted onloadstart attribute of an IMG element) in a text field. Note: Researchers have claimed that this issue is not within the product itself, but is intended behavior in a web… | |
| Modificada | Alta (10) | 1.7% | — | Goosequill Remoteeditor | 31/12/2004 | 16/6/2026 | Unknown vulnerability in RemoteEditor before 0.1.1 has unknown impact and attack vectors, related to "oversize submissions." | |
| Modificada | Alta (7.5) | 1.4% | — | Goosequill Audienceconnect Remoteeditor | 31/12/2004 | 16/6/2026 | Unknown vulnerability in the "access code" in RemoteEditor before 0.1.6 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions. | |
| Modificada | Alta (10) | 1.4% | — | Goosequill Audienceconnect | 31/12/2004 | 16/6/2026 | Unknown vulnerability in the "admin of paypal email addresses" in AudienceConnect before 1.0.beta.21 has unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Goosequill Audienceconnect Secureeditor | 31/12/2004 | 16/6/2026 | Unknown vulnerability in the "access code" in SecureEditor before 0.1.2 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions. |