Kaliforms
Kaliforms Kali Forms: vulnerabilidades y CVE
Kaliforms Kali Forms tiene 12 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses7
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-81276 | Media (5.3) | 0.29% | — | 27 ago 2026 | Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions. |
| CVE-2026-16144 | Alta (8.1) | 1.2% | — | 1 ago 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient… |
| CVE-2026-15395 | Alta (7.2) | 0.43% | — | 17 jul 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient… |
| CVE-2026-11580 | Media (5.5) | 0.32% | — | 15 jul 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or… |
| CVE-2026-9107 | Media (6.4) | 0.42% | — | 1 jul 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter in all versions up to, and including, 2.4.13… |
| CVE-2026-3584 | Crítica (9.8) | 4.4% | — | 20 mar 2026 | The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping… |
| CVE-2026-1860 | Media (4.3) | 0.30% | — | 18 feb 2026 | The Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.8. This is due to the `get_items_permissions_check()` permission callback on the… |
| CVE-2025-3201 | Media (5.9) | 0.25% | — | 16 may 2025 | The Contact Form builder with drag & drop for WordPress WordPress plugin before 2.4.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored… |
| CVE-2024-22305 | Alta (8.1) | 0.45% | — | 31 ene 2024 | Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress – Kali… |
| CVE-2020-36720 | Alta (7.1) | 0.79% | — | 7 jun 2023 | The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible… |
| CVE-2020-36717 | Alta (8.8) | 0.48% | — | 7 jun 2023 | The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plugin's function. This makes it possible… |
| CVE-2020-36712 | Media (5.3) | 0.73% | — | 7 jun 2023 | The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege… |