Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2628▼ 312 respecto a la semana anterior
Críticas / altas1351▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.31%—Simple Captcha With Cloudflare TurnstileAI11/9/202611/9/2026
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
AplazadaMedia (5.6)0.25%—Simple Cloudflare TurnstileAI10/9/202610/9/2026
Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.
AplazadaMedia (6.5)0.28%—Cloudflare TurnstileAI10/9/202610/9/2026
Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.
AplazadaMedia (5.3)0.16%—Simple Captcha With Cloudflare TurnstileAI7/8/202626/8/2026
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and…
AplazadaMedia (5.3)0.36%—Simple Cloudflare TurnstileAI15/6/202617/6/2026
Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.
ModificadaMedia (5.4)0.74%—Replywp Simple Cloudfare Turnstile27/9/202317/6/2026
The Simple Cloudflare Turnstile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gravity-simple-turnstile' shortcode in versions up to, and including, 1.23.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers…