Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.19% | — | W3sc Elementor TO Zoho CRMAI | 18/7/2026 | 22/7/2026 | The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes it possible for unauthenticated attackers to modify the plugin's Zoho CRM integration… | |
| Aplazada | Media (4.9) | 0.32% | — | Catalystconnect Catalyst Connect Zoho CRM Client PortalAI | 11/7/2026 | 29/9/2026 | The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Aplazada | Media (5.4) | 0.30% | — | Zoho CRM Lead MagnetAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.8.1.9. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Zoho CRM AND Bigin | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.9. | |
| Aplazada | Media (4.7) | 0.22% | — | Crmperks WP Gravity Forms Zoho CRM AND BiginAI | 27/10/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Phishing.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.8. | |
| Aplazada | Alta (7.1) | 0.12% | — | W3S Cloud Technology W3scloud Contact Form 7 TO Zoho CRMAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in W3S Cloud Technology W3SCloud Contact Form 7 to Zoho CRM w3s-cf7-zoho allows Stored XSS.This issue affects W3SCloud Contact Form 7 to Zoho CRM: from n/a through <= 3.2. | |
| Aplazada | Crítica (9.8) | 0.60% | — | Contact Form 7AIZoho CRMAICrmperks Integration FOR Contact Form 7 AND Zoho CRM BiginAI | 17/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin cf7-zoho allows Object Injection.This issue affects Integration for Contact Form 7 and Zoho CRM, Bigin: from n/a through <= 1.3.0. | |
| Aplazada | Media (4.7) | 0.32% | — | Formsintegrations Integrations OF Zoho CRM With Elementor FormAI | 7/5/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in formsintegrations Integrations of Zoho CRM with Elementor form integrations-of-zoho-crm-with-elementor-form allows Phishing.This issue affects Integrations of Zoho CRM with Elementor form: from n/a through <= 1.0.8. | |
| Aplazada | Alta (8.5) | 0.40% | — | Zohocorp Zoho CRM Lead MagnetAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows SQL Injection.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.7.9.7. | |
| Modificada | Media (6.1) | 0.47% | — | Crmperks Integration FOR Woocommerce AND Zoho Crm, Books, Invoice, Inventory, Bigin | 19/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin.This issue affects Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin: from n/a before 1.3.7. | |
| Modificada | Media (4.8) | 0.37% | — | Catalystconnect Catalyst Connect Zoho CRM Client Portal | 10/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Catalyst Connect Catalyst Connect Zoho CRM Client Portal plugin <= 2.0.0 versions. | |
| Modificada | Media (6.1) | 0.46% | — | Catalystconnect Zoho CRM Client Portal | 27/6/2023 | 17/6/2026 | The Catalyst Connect Zoho CRM Client Portal WordPress plugin before 2.1.0 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admin. | |
| Modificada | Media (4.8) | 0.44% | — | Crmperks Integration FOR Contact Form 7 AND Zoho Crm, Bigin | 19/6/2023 | 17/6/2026 | The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin | |
| Modificada | Alta (8.8) | 0.26% | — | Crmperks Integration FOR Contact Form 7 AND Zoho Crm, Bigin | 26/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin plugin <= 1.2.2 versions. | |
| Modificada | Media (6.5) | 3.3% | — | Zohocorp Zoho CRM Lead Magnet | 9/11/2022 | 17/6/2026 | Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress. | |
| Modificada | Media (5.4) | 1.1% | — | Zohocorp Zoho CRM Lead Magnet | 5/10/2021 | 17/6/2026 | A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenever… |