Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.1)0.31%—Drupal Webform RestAI25/8/202628/8/2026
Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.
AplazadaMedia (5.3)0.32%—Mailercloud-integrate-webforms-synchronize-contactsAI8/4/202624/7/2026
Missing Authorization vulnerability in mailercloud Mailercloud – Integrate webforms and synchronize website contacts mailercloud-integrate-webforms-synchronize-contacts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mailercloud – Integrate webforms and synchronize website…
ModificadaAlta (7)0.33%—Webform Multiple File Upload Project Webform Multiple File Upload26/11/202517/6/2026
Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name renderer. An unauthenticated attacker can exploit this vulnerability by uploading a file with a malicious filename containing JavaScript code (e.g., "<img src=1 onerror=alert(document.domain)>") to a…
ModificadaAlta (7.5)1.5%—Webform Report Project Webform Report1/1/202117/6/2026
The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml page. NOTE: This project is not covered by Drupal's security advisory policy.
ModificadaMedia (6.1)0.72%—Mageme Webforms PRO M229/6/202017/6/2026
XSS exists in the WebForms Pro M2 extension before 2.9.17 for Magento 2 via the textarea field.
ModificadaCrítica (9.8)1.4%—Systematic Iris Webforms12/11/201917/6/2026
Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication.
ModificadaMedia (5.3)1.3%—Systematic Iris Webforms12/11/201917/6/2026
Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with ../ (and variations), it is possible to list all the directories and check if a particular file exists.
ModificadaBaja (3.5)0.95%—Webform Matrix Component Project Webform Matrix Component18/8/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Webform Matrix Component module 7.x-4.x before 7.x-4.13 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (3.5)1.1%—Webform Project Webform16/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.23, 7.x-3.x before 7.x-3.23, and 7.x-4.x before 7.x-4.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a component name in the recipient (To) address of an email.
ModificadaBaja (3.5)1.1%—Ubercart Webform Checkout Pane Project Ubercart Webform Checkout Pane15/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Ubercart Webform Checkout Pane module 6.x-3.x before 6.x-3.10 and 7.x-3.x before 7.x-3.11 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)0.73%—Webform Multiple File Upload Project Webform Multiple File Upload15/6/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the Webform Multiple File Upload module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of certain users for requests that delete files via unspecified vectors.
ModificadaBaja (3.5)1.1%—Webform Project Webform15/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.22, 7.x-3.x before 7.x-3.22, and 7.x-4.x before 7.x-4.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title, which is used as the default title of a webform block.
ModificadaBaja (3.5)0.95%—Webform Project Webform15/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the view-based webform results table in the Webform module 7.x-4.x before 7.x-4.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a webform.
ModificadaBaja (3.5)0.95%—Ubercart Webform Integration Project Ubercart Webform Integration15/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Ubercart Webform Integration module before 6.x-1.8 and 7.x before 7.x-2.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (3.5)0.94%—Webform Prepopulate Block Project Webform Prepopulate Block17/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Webform prepopulate block module before 7.x-3.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (3.5)0.95%—Webform Invitation Project Webform Invitation9/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Webform Invitation module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.4 for Drupal allows remote authenticated users with the Webform: Create new content, Webform: Edit own content, or Webform: Edit any content permission to inject arbitrary web script or HTML via a…
ModificadaMedia (4.3)1.0%—Payment FOR Webform Project Payment FOR Webform25/10/201416/6/2026
The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allows remote anonymous users to use the payment of other anonymous users when submitting a form that requires payment.
ModificadaBaja (3.5)1.1%—Webform Project Webform17/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.20, 7.x-3.x before 7.x-3.20, and 7.x-4.x before 7.x-4.0-beta2 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a field label title, when two fields have the same form_key.
ModificadaBaja (3.5)1.0%—Webform Validation Project Webform Validation17/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Webform Validation module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a component name text.
ModificadaMedia (6.5)8.9%—Devexpress Aspxfilemanager Control FOR Webforms AND MVC6/6/201417/6/2026
Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter.
ModificadaMedia (4.3)1.3%—Nathan Haug Webform24/6/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.19 for Drupal allows remote authenticated users with the "edit own webform content" or "edit all webform content" permissions to inject arbitrary web script or HTML via a component label.
ModificadaMedia (5)1.4%—Coleman Watts Webform Civicrm3/12/201216/6/2026
The default configuration for the Webform CiviCRM Integration module 7.x-3.x before 7.x-3.2 has "Enforce Permissions" disabled, which allows remote attackers to obtain contact information by reading webforms.
ModificadaBaja (2.1)1.0%—Svendecabooter Webform Validation20/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Webform Validation module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with permissions to "update Webform nodes" to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (2.1)1.3%—Nathan Haug Webform18/9/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in components/select.inc in the Webform module 6.x-3.x before 6.x-3.17 and 7.x-3.x before 7.x-3.17 for Drupal, when the "Select (or other)" module is enabled, allow remote authenticated users with the create webform content permission to inject arbitrary web script…
ModificadaMedia (4.3)1.0%—Jrbcs Webform Report25/8/201016/6/2026
Cross-site scripting (XSS) vulnerability in the Webform report module 5.x and 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via a submission.