Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.29% | — | Brainstormforce SureformsAI | 5/9/2026 | 8/9/2026 | The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.34% | — | Brainstormforce SureformsAI | 3/9/2026 | 7/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5. | |
| Aplazada | Alta (8.8) | 0.56% | — | Brainstormforce SureformsAI | 18/8/2026 | 3/9/2026 | CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is… | |
| Aplazada | Alta (7.5) | 0.58% | — | Brainstormforce SureformsAI | 18/8/2026 | 3/9/2026 | The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface,… | |
| Aplazada | Media (6.4) | 0.36% | — | Brainstormforce SureformsAI | 1/8/2026 | 12/8/2026 | The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headingWrapper' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.9) | 0.29% | — | Brainstormforce SureformsAI | 14/7/2026 | 14/7/2026 | The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamically-sourced (variable/hidden) payment amount, allowing unauthenticated users to underpay for the configured product or subscription. Forms using a fixed configured price are not affected. | |
| Aplazada | Alta (7.5) | 0.47% | — | Sureforms Drag AND Drop Form BuilderAI | 10/7/2026 | 14/7/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 2.2.1. This is due to the plugin accepting the payment amount directly from user-controlled POST data in the 'create_payment_intent' and… | |
| Aplazada | Alta (7.3) | 0.30% | — | Brainstormforce Sureforms PROAI | 29/4/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0. | |
| Aplazada | Alta (7.5) | 1.2% | — | Brainstormforce SureformsAI | 28/3/2026 | 17/6/2026 | The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.5.2. This is due to the create_payment_intent() function performing a payment validation solely based on the value of a user-controlled parameter.… | |
| Aplazada | Alta (7.2) | 0.37% | — | Brainstormforce SureformsAI | 21/12/2025 | 28/9/2026 | The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Media (5.3) | 0.20% | — | Brainstormforce SureformsAI | 19/11/2025 | 17/6/2026 | The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the plugin distributing generic WordPress REST API nonces (wp_rest) to unauthenticated users via the 'wp_ajax_nopriv_rest-nonce' action. While the plugin legitimately needs… | |
| Aplazada | Media (5.3) | 0.79% | — | Brainstormforce SureformsAI | 13/11/2025 | 17/6/2026 | The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to the metadata. This… | |
| Aplazada | Media (4.3) | 0.25% | — | Brainstormforce SureformsAI | 14/10/2025 | 17/6/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. This makes it… | |
| Aplazada | Baja (3.5) | 0.19% | — | Brainstormforce SureformsAI | 23/9/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.9.1 does not sanitise and escape some parameters when outputing them in the page, which could allow admin and above users to perform Cross-Site Scripting attacks. | |
| Aplazada | Media (4.3) | 0.19% | — | Brainstormforce SureformsAI | 20/9/2025 | 17/6/2026 | The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for… | |
| Analizada | Media (5.8) | 0.18% | — | Brainstormforce Sureforms | 1/8/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users. | |
| Analizada | Alta (7.5) | 0.55% | — | Brainstormforce Sureforms | 9/7/2025 | 17/6/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.3 via the use of file_exists() in the delete_entry_files() function without restriction on the path provided. This makes it possible for unauthenticated… | |
| Analizada | Alta (8.1) | 1.0% | — | Brainstormforce Sureforms | 9/7/2025 | 17/6/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to delete arbitrary… | |
| Analizada | Baja (3.5) | 0.27% | — | Brainstormforce Sureforms | 2/5/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Baja (3.5) | 0.31% | — | Brainstormforce Sureforms | 2/5/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.9) | 0.35% | — | Brainstormforce Sureforms | 30/4/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action | |
| Analizada | Media (5.3) | 0.34% | — | Brainstormforce Sureforms | 8/1/2025 | 17/6/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated attackers to export data from password… |