Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1465▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.24% | — | Hcaptcha FOR WPAI | 1/10/2026 | 1/10/2026 | Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions. | |
| Aplazada | Media (4.8) | 0.19% | — | Captcha CodeAI | 23/9/2026 | 23/9/2026 | Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Invisible Anti Spam AND CaptchaAI | 17/9/2026 | 18/9/2026 | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather than validating it, allowing any authenticated user, such as a subscriber, to… | |
| Aplazada | Media (6.5) | 0.31% | — | Simple Captcha With Cloudflare TurnstileAI | 11/9/2026 | 11/9/2026 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | |
| Aplazada | Media (6.5) | 0.31% | — | Contact Form 7 CaptchaAI | 9/9/2026 | 9/9/2026 | The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | |
| Analizada | Baja (3.7) | 0.32% | — | Captcha Protected Page Project Captcha Protected Page | 2/9/2026 | 9/9/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2. | |
| Aplazada | Media (4.9) | 0.50% | — | Invisible Anti Spam CaptchaAI | 15/8/2026 | 20/8/2026 | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via Pattern JSON Keys/Values in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Alta (7.2) | 0.46% | — | Invisible Anti Spam AND CaptchaAI | 15/8/2026 | 20/8/2026 | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (4.9) | 0.58% | — | Invisible Anti Spam AND CaptchaAI | 15/8/2026 | 20/8/2026 | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via the 'key' parameter in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Media (5.3) | 0.16% | — | Simple Captcha With Cloudflare TurnstileAI | 7/8/2026 | 26/8/2026 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and… | |
| Aplazada | Media (5.3) | 0.33% | — | Wpwhitesecurity Captcha 4WPAI | 6/8/2026 | 12/8/2026 | Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions. | |
| Analizada | Crítica (10) | 0.81% | — | Aimy-extensions Aimy Captcha-less Form Guard | 29/7/2026 | 5/8/2026 | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution. | |
| Aplazada | Media (6.5) | 0.22% | — | Hitesh Chandwani Recaptcha FOR Asgaros ForumAIGoogle RecaptchaAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 & v3) for Asgaros Forum recaptcha-for-asgaros-forum allows DOM-Based XSS.This issue affects reCAPTCHA (v2 & v3) for Asgaros Forum: from n/a through <= 1.1.0. | |
| Aplazada | Media (4.3) | 0.19% | — | Blue CaptchaAI | 24/6/2026 | 25/6/2026 | The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1. This is due to missing or incorrect nonce validation on the main admin panel (blcap_main_page) and on the Hall of Shame and Log subpages, which accept a 'blcap_action' / 'action' parameter from… | |
| Aplazada | Alta (8.8) | 0.59% | — | Devnath Verma WP CaptchaAI | 5/6/2026 | 17/6/2026 | The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.38. This is due to the ajax_run_tool() AJAX handler relying solely on a nonce check (check_ajax_referer) for… | |
| Aplazada | Alta (8.8) | 0.79% | — | Devnath Verma WP CaptchaAI | 5/6/2026 | 17/6/2026 | The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 5.38. This is due to a capability check in the save_ajax() function of the licensing module, combined with… | |
| Aplazada | Alta (7.2) | 0.35% | — | Login NO Captcha RecaptchaAI | 28/5/2026 | 17/6/2026 | The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to the `authenticate()` function storing the unsanitized output of `basename($_SERVER['PHP_SELF'])` in the… | |
| Aplazada | Baja (3.5) | 0.24% | — | Recaptcha BY WebdesignbyAI | 23/4/2026 | 17/6/2026 | The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputting it in a JavaScript string context via the grecaptcha_js() function. This allows administrators on multisite installations (who do not have the unfiltered_html capability) to inject arbitrary… | |
| Aplazada | Media (4.3) | 0.20% | — | KcaptchaAI | 22/4/2026 | 17/6/2026 | The Kcaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.1. This is due to missing nonce validation in the plugin's settings page handler (admin/setting.php). The settings form does not include a wp_nonce_field() and the form processing code does not call… | |
| Analizada | Media (6.1) | 0.33% | — | Libops Captcha Protect | 31/3/2026 | 24/7/2026 | Captcha Protect is a Traefik middleware to add an anti-bot challenge to individual IPs in a subnet when traffic spikes are detected from that subnet. Prior to version 1.12.2, a reflected cross-site scripting (XSS) vulnerability exists in github.com/libops/captcha-protect. The challenge page accepted a client-supplied… | |
| Analizada | Media (6.5) | 0.34% | — | Arnabdotorg Captcha | 25/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA allows Functionality Bypass.This issue affects CAPTCHA: from 0.0.0 before 1.17.0, from 2.0.0 before 2.0.10. | |
| Aplazada | Media (4.3) | 0.16% | — | Conditional CaptchaAI | 22/2/2026 | 17/6/2026 | The Conditional CAPTCHA WordPress plugin through 4.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue | |
| Aplazada | Media (5.3) | 0.24% | — | Hcaptcha FOR WPAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in hcaptcha hCaptcha for WP hcaptcha-for-forms-and-more allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects hCaptcha for WP: from n/a through <= 4.21.1. | |
| Aplazada | Media (4.3) | 0.22% | — | ZT CaptchaAI | 24/1/2026 | 17/6/2026 | The ZT Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to improper nonce validation on the save_ztcpt_captcha_settings action where the nonce check can be bypassed by sending an empty token value. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.17% | — | MtcaptchaAI | 7/1/2026 | 17/6/2026 | The MTCaptcha WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin settings, including… |