« Volver al listado

Hashthemes

Hashthemes Hash Form: vulnerabilidades y CVE

Hashthemes Hash Form tiene 8 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses3
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-81780Crítica (10)0.52%—31 ago 2026
Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
CVE-2026-78292Crítica (9.8)0.56%—27 ago 2026
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
CVE-2026-78280Media (4.3)0.14%—24 ago 2026
Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.
CVE-2025-47468Media (4.3)0.16%—7 may 2025
Cross-Site Request Forgery (CSRF) vulnerability in hashthemes Hash Form hash-form allows Cross Site Request Forgery.This issue affects Hash Form: from n/a through <= 1.2.8.
CVE-2024-12201Media (4.3)0.38%—12 dic 2024
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check when creating form styles in all versions up to, and including, 1.2.1. This makes it…
CVE-2024-9417Media (6.1)0.37%—5 oct 2024
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in the 'handleUpload' function in all versions up to, and including, 1.1.9.…
CVE-2024-5085Crítica (9.8)0.78%—23 may 2024
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input in the 'process_entry' function.…
CVE-2024-5084Crítica (9.8)51%—23 may 2024
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0.…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1059 Command and Scripting Interpreter1
  3. T1505.003 Web Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Hashthemes