Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 295 respecto a la semana anterior
Críticas / altas1354▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.16% | — | Gvectors WpforoAI | 25/9/2026 | 25/9/2026 | The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing unauthenticated attackers to bypass the limit by spoofing the header and exhaust the site owner's metered AI… | |
| Aplazada | Media (6.4) | 0.20% | — | Gvectors WpforoAI | 25/9/2026 | 25/9/2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. This is due to insufficient input sanitization and output escaping in the profile_update action — the raw $_POST['data'] array is copied into a $custom_fields… | |
| Aplazada | Alta (7.5) | 0.31% | — | Gvectors Wpforo ForumAI | 24/9/2026 | 24/9/2026 | The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before… | |
| Aplazada | Media (6.5) | 0.22% | — | Gvectors Wpforo ForumAI | 23/9/2026 | 23/9/2026 | Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions. | |
| Aplazada | Media (4.3) | 0.39% | — | Gvectors WpforoAI | 22/9/2026 | 23/9/2026 | The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to take… | |
| Aplazada | Alta (7.5) | 0.55% | — | Gvectors WpforoAI | 28/8/2026 | 28/8/2026 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.25% | — | Gvectors WpforoAI | 4/8/2026 | 26/8/2026 | The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned… | |
| Aplazada | Media (5.4) | 0.23% | — | Gvectors WpforoAI | 1/8/2026 | 26/8/2026 | The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile,… | |
| Aplazada | Media (5.4) | 0.29% | — | Gvectors Wpforo ForumAI | 31/7/2026 | 26/8/2026 | The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user. | |
| Aplazada | Media (6.4) | 0.36% | — | Gvectors WpforoAI | 16/7/2026 | 16/7/2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject… | |
| Aplazada | Alta (8.5) | 0.36% | — | Gvectors WpforoAI | 26/6/2026 | 26/6/2026 | Contributor SQL Injection in wpForo Forum <= 3.0.9 versions. | |
| Aplazada | Crítica (9.8) | 0.61% | — | Gvectors WpforoAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | PHPAIGvectors WpforoAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Gvectors Wpforo ForumAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Gvectors WpforoAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions. | |
| Aplazada | Crítica (9.1) | 0.44% | — | Gvectors Wpforo ForumAI | 1/6/2026 | 22/7/2026 | Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6. | |
| Aplazada | Alta (8.1) | 0.95% | — | Gvectors WpforoAI | 20/4/2026 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the value of file-type custom profile fields, allowing authenticated users to store an arbitrary path… | |
| Aplazada | Media (6.5) | 0.45% | — | Gvectors WpforoAI | 17/4/2026 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the `edit()` method of `classes/Posts.php` in all versions up to, and including, 2.4.16. The `post_edit` action handler in `Actions.php` passes… | |
| Aplazada | Alta (7.1) | 0.63% | — | Gvectors WpforoAI | 11/4/2026 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept arbitrary user-supplied data[*] arrays from $_REQUEST and store them as postmeta without restricting which… | |
| Aplazada | Alta (8.8) | 0.58% | — | Gvectors WpforoAI | 4/4/2026 | 24/7/2026 | The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This makes it possible for authenticated attackers, with subscriber level access and above, to delete… | |
| Analizada | Alta (8.8) | 0.52% | — | Gvectors Wpforo Forum | 28/2/2026 | 17/6/2026 | wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql() sanitization on unquoted identifiers. Attackers exploit the wpfob parameter with CASE WHEN payloads to perform blind boolean extraction of credentials from the… | |
| Analizada | Media (4.8) | 0.33% | — | Gvectors Wpforo Forum | 28/2/2026 | 17/6/2026 | wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows administrators to inject persistent JavaScript via forum description fields echoed without output escaping across multiple theme template files. On multisite installations or with a compromised admin account, attackers set a forum… | |
| Analizada | Media (4.8) | 0.33% | — | Gvectors Wpforo Forum | 28/2/2026 | 17/6/2026 | wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows script injection via forum URL data output into an inline script block using json_encode without the JSON_HEX_TAG flag. Attackers set a forum slug containing a closing script tag or unescaped single quote to break out of the… | |
| Analizada | Media (6.9) | 0.48% | — | Gvectors Wpforo Forum | 28/2/2026 | 17/6/2026 | wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topics via the global RSS feed endpoint. Attackers request the RSS feed without a forum ID parameter, bypassing the privacy and status WHERE clauses that are only applied when… | |
| Analizada | Media (5.1) | 0.30% | — | Gvectors Wpforo Forum | 28/2/2026 | 17/6/2026 | wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload functionality. Attackers upload a crafted SVG containing CSS injection or JavaScript event handlers that execute in the browsers of any user… |