Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | CformsiiAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Bgermann CformsiiAI | 25/5/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affects CformsII: from n/a through 15.1.3. | |
| Aplazada | Alta (7.1) | 0.37% | — | Oliver Seidel CformsiiAIBastian Germann CformsiiAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann CformsII allows Stored XSS.This issue affects CformsII: from n/a through 15.0.5. | |
| Modificada | Media (4.8) | 0.32% | — | Cformsii Project Cformsii | 8/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a through 15.0.5. | |
| Modificada | Alta (8.8) | 0.27% | — | Cformsii Project Cformsii | 15/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions. | |
| Modificada | Media (6.1) | 0.91% | — | Cformsii Project Cformsii | 22/8/2019 | 17/6/2026 | The cforms2 plugin before 10.5 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.93% | — | Cformsii Project Cformsii | 22/8/2019 | 17/6/2026 | The cforms2 plugin before 10.2 for WordPress has XSS. | |
| Modificada | Crítica (9.8) | 1.8% | — | Cformsii Project Cformsii | 22/8/2019 | 17/6/2026 | The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries. | |
| Modificada | Crítica (9.8) | 1.8% | — | Cformsii Project Cformsii | 22/8/2019 | 17/6/2026 | The cforms2 plugin before 14.6.10 for WordPress has SQL injection. | |
| Modificada | Media (6.1) | 0.92% | — | Cformsii Project Cformsii | 21/8/2019 | 17/6/2026 | The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 0.93% | — | Cformsii Project Cformsii | 21/8/2019 | 17/6/2026 | The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php. | |
| Modificada | Alta (8.8) | 0.74% | — | Cformsii Project Cformsii | 20/8/2019 | 17/6/2026 | The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field. | |
| Modificada | Alta (7.5) | 14% | — | Deliciousdays Cformsii | 8/1/2015 | 17/6/2026 | Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file via a direct request to the file in the default… |