Hashthemes
Hashthemes Hash Form: vulnerabilidades y CVE
Hashthemes Hash Form tiene 8 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses3
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-81780 | Crítica (10) | 0.52% | — | 31 ago 2026 | Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. |
| CVE-2026-78292 | Crítica (9.8) | 0.56% | — | 27 ago 2026 | Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions. |
| CVE-2026-78280 | Media (4.3) | 0.14% | — | 24 ago 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions. |
| CVE-2025-47468 | Media (4.3) | 0.16% | — | 7 may 2025 | Cross-Site Request Forgery (CSRF) vulnerability in hashthemes Hash Form hash-form allows Cross Site Request Forgery.This issue affects Hash Form: from n/a through <= 1.2.8. |
| CVE-2024-12201 | Media (4.3) | 0.38% | — | 12 dic 2024 | The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check when creating form styles in all versions up to, and including, 1.2.1. This makes it… |
| CVE-2024-9417 | Media (6.1) | 0.37% | — | 5 oct 2024 | The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in the 'handleUpload' function in all versions up to, and including, 1.1.9.… |
| CVE-2024-5085 | Crítica (9.8) | 0.78% | — | 23 may 2024 | The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input in the 'process_entry' function.… |
| CVE-2024-5084 | Crítica (9.8) | 51% | — | 23 may 2024 | The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0.… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.