Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1465▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
–

113 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.24%—Hcaptcha FOR WPAI1/10/20261/10/2026
Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions.
AplazadaMedia (4.8)0.19%—Captcha CodeAI23/9/202623/9/2026
Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.
AplazadaMedia (4.3)0.25%—Invisible Anti Spam AND CaptchaAI17/9/202618/9/2026
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather than validating it, allowing any authenticated user, such as a subscriber, to…
AplazadaMedia (6.5)0.31%—Simple Captcha With Cloudflare TurnstileAI11/9/202611/9/2026
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
AplazadaMedia (6.5)0.31%—Contact Form 7 CaptchaAI9/9/20269/9/2026
The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
AnalizadaBaja (3.7)0.32%—Captcha Protected Page Project Captcha Protected Page2/9/20269/9/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.
AplazadaMedia (4.9)0.50%—Invisible Anti Spam CaptchaAI15/8/202620/8/2026
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via Pattern JSON Keys/Values in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaAlta (7.2)0.46%—Invisible Anti Spam AND CaptchaAI15/8/202620/8/2026
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
AplazadaMedia (4.9)0.58%—Invisible Anti Spam AND CaptchaAI15/8/202620/8/2026
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via the 'key' parameter in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
AplazadaMedia (5.3)0.16%—Simple Captcha With Cloudflare TurnstileAI7/8/202626/8/2026
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and…
AplazadaMedia (5.3)0.33%—Wpwhitesecurity Captcha 4WPAI6/8/202612/8/2026
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
AnalizadaCrítica (10)0.81%—Aimy-extensions Aimy Captcha-less Form Guard29/7/20265/8/2026
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
AplazadaMedia (6.5)0.22%—Hitesh Chandwani Recaptcha FOR Asgaros ForumAIGoogle RecaptchaAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 &amp; v3) for Asgaros Forum recaptcha-for-asgaros-forum allows DOM-Based XSS.This issue affects reCAPTCHA (v2 &amp; v3) for Asgaros Forum: from n/a through <= 1.1.0.
AplazadaMedia (4.3)0.19%—Blue CaptchaAI24/6/202625/6/2026
The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1. This is due to missing or incorrect nonce validation on the main admin panel (blcap_main_page) and on the Hall of Shame and Log subpages, which accept a 'blcap_action' / 'action' parameter from…
AplazadaAlta (8.8)0.59%—Devnath Verma WP CaptchaAI5/6/202617/6/2026
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.38. This is due to the ajax_run_tool() AJAX handler relying solely on a nonce check (check_ajax_referer) for…
AplazadaAlta (8.8)0.79%—Devnath Verma WP CaptchaAI5/6/202617/6/2026
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 5.38. This is due to a capability check in the save_ajax() function of the licensing module, combined with…
AplazadaAlta (7.2)0.35%—Login NO Captcha RecaptchaAI28/5/202617/6/2026
The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to the `authenticate()` function storing the unsanitized output of `basename($_SERVER['PHP_SELF'])` in the…
AplazadaBaja (3.5)0.24%—Recaptcha BY WebdesignbyAI23/4/202617/6/2026
The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputting it in a JavaScript string context via the grecaptcha_js() function. This allows administrators on multisite installations (who do not have the unfiltered_html capability) to inject arbitrary…
AplazadaMedia (4.3)0.20%—KcaptchaAI22/4/202617/6/2026
The Kcaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.1. This is due to missing nonce validation in the plugin's settings page handler (admin/setting.php). The settings form does not include a wp_nonce_field() and the form processing code does not call…
AnalizadaMedia (6.1)0.33%—Libops Captcha Protect31/3/202624/7/2026
Captcha Protect is a Traefik middleware to add an anti-bot challenge to individual IPs in a subnet when traffic spikes are detected from that subnet. Prior to version 1.12.2, a reflected cross-site scripting (XSS) vulnerability exists in github.com/libops/captcha-protect. The challenge page accepted a client-supplied…
AnalizadaMedia (6.5)0.34%—Arnabdotorg Captcha25/3/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA allows Functionality Bypass.This issue affects CAPTCHA: from 0.0.0 before 1.17.0, from 2.0.0 before 2.0.10.
AplazadaMedia (4.3)0.16%—Conditional CaptchaAI22/2/202617/6/2026
The Conditional CAPTCHA WordPress plugin through 4.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue
AplazadaMedia (5.3)0.24%—Hcaptcha FOR WPAI19/2/202617/6/2026
Missing Authorization vulnerability in hcaptcha hCaptcha for WP hcaptcha-for-forms-and-more allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects hCaptcha for WP: from n/a through <= 4.21.1.
AplazadaMedia (4.3)0.22%—ZT CaptchaAI24/1/202617/6/2026
The ZT Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to improper nonce validation on the save_ztcpt_captcha_settings action where the nonce check can be bypassed by sending an empty token value. This makes it possible for…
AplazadaMedia (4.3)0.17%—MtcaptchaAI7/1/202617/6/2026
The MTCaptcha WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin settings, including…