Infility
Infility Global: vulnerabilidades y CVE
Infility Global tiene 14 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses7
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-10734 | Alta (7.2) | 0.40% | — | 16 ago 2026 | The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up to, and including, 2.15.21 due to insufficient input sanitization and output… |
| CVE-2026-7842 | Media (6.8) | 0.39% | — | 23 jun 2026 | The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validate the orderby and order parameters in the import_list(), url_detail(), and file_detail() admin page callbacks… |
| CVE-2026-8685 | Media (6.5) | 0.41% | — | 20 may 2026 | The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all versions up to, and including, 2.15.16. This is due to insufficient escaping on user supplied… |
| CVE-2025-15268 | Alta (7.5) | 0.46% | — | 4 feb 2026 | The Infility Global plugin for WordPress is vulnerable to unauthenticated SQL Injection via the 'infility_get_data' API action in all versions up to, and including, 2.14.46. This is due to insufficient escaping on the… |
| CVE-2025-68864 | Alta (7.1) | 0.27% | — | 22 ene 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infility Infility Global infility-global allows Stored XSS.This issue affects Infility Global: from n/a through <=… |
| CVE-2025-68865 | Crítica (9.3) | 0.27% | — | 5 ene 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global infility-global allows SQL Injection.This issue affects Infility Global: from n/a through <=… |
| CVE-2025-12968 | Alta (8.8) | 0.59% | — | 12 dic 2025 | The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in all versions up to, and including, 2.14.42. This is due to the `upload_file`… |
| CVE-2025-47650 | Media (6.5) | 0.43% | — | 20 ago 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Infility Infility Global infility-global allows Path Traversal.This issue affects Infility Global: from n/a through <=… |
| CVE-2025-47652 | Alta (7.1) | 0.24% | — | 16 jul 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infility Infility Global infility-global allows Reflected XSS.This issue affects Infility Global: from n/a through <=… |
| CVE-2025-52774 | Alta (7.1) | 0.21% | — | 27 jun 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infility Infility Global infility-global allows Reflected XSS.This issue affects Infility Global: from n/a through <=… |
| CVE-2025-47651 | Alta (8.5) | 0.31% | — | 9 jun 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global infility-global allows SQL Injection.This issue affects Infility Global: from n/a through <=… |
| CVE-2024-12723 | Media (6.1) | 0.28% | — | 28 ene 2025 | The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege… |
| CVE-2024-12290 | Media (6.1) | 0.37% | — | 7 ene 2025 | The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘set_type’ parameter in all versions up to, and including, 2.9.8 due to insufficient input sanitization and output… |
| CVE-2024-11496 | Media (6.5) | 0.33% | — | 7 ene 2025 | The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the infility_global_ajax function in all versions up to, and including, 2.9.8. This makes… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.