Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.20% | — | Wpexperts Contact Form 7 HoneypotAI | 1/10/2026 | 1/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WPExperts CF7 Apps contact-form-7-honeypot allows Retrieve Embedded Sensitive Data.This issue affects CF7 Apps: from n/a through 3.7.2. | |
| Aplazada | Alta (7.2) | 0.24% | — | Bizessentials Business Essentials FOR Contact Form 7AI | 1/10/2026 | 1/10/2026 | The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (7.2) | 0.40% | — | Themefic Ultimate Addons FOR Contact Form 7AI | 30/9/2026 | 30/9/2026 | Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. | |
| Aplazada | Alta (7.2) | 0.19% | — | Htplugins HT Contact FormAI | 29/9/2026 | 30/9/2026 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Ultra Addons FOR Contact Form 7AI | 26/9/2026 | 28/9/2026 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the… | |
| Aplazada | Alta (7.2) | 0.25% | — | HT Contact FormAI | 25/9/2026 | 25/9/2026 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'form_data' Rich Text Field via Draft Save/Resume in all versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.5) | 0.16% | — | Contact Form 7AIThemefic Ultimate Addons FOR Contact Form 7AI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions. | |
| Aplazada | Media (6.5) | 0.26% | — | Advanced Contact Form 7 DBAI | 23/9/2026 | 23/9/2026 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (5.8) | 0.32% | — | Zealousweb Generate PDF Using Contact Form 7AI | 18/9/2026 | 18/9/2026 | The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the server request internal resources and read the response back through the generated PDF. | |
| Aplazada | Media (5.3) | 0.34% | — | Contact Form TO Chat AppsAI | 13/9/2026 | 14/9/2026 | The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entries of any form created with a supported third-party form Contact Form to Chat Apps |… | |
| Aplazada | Media (4.3) | 0.21% | — | Advanced Contact Form 7 DBAI | 10/9/2026 | 10/9/2026 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above,… | |
| Aplazada | Media (6.5) | 0.31% | — | Contact Form 7 CaptchaAI | 9/9/2026 | 9/9/2026 | The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | |
| Aplazada | Alta (7.2) | 0.24% | — | Bestwebsoft Contact Form TO DBAI | 9/9/2026 | 9/9/2026 | The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (4.8) | 0.24% | — | Redirection FOR Contact Form 7AI | 6/9/2026 | 8/9/2026 | The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode… | |
| Aplazada | Alta (7.2) | 0.58% | — | Contact Form BY SupsysticAI | 5/9/2026 | 8/9/2026 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (4.3) | 0.49% | — | Custom Contact FormsAI | 5/9/2026 | 8/9/2026 | The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Calculation FOR Contact Form 7AI | 3/9/2026 | 3/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions. | |
| Aplazada | Alta (8.1) | 0.54% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 21/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server. | |
| Aplazada | Baja (3.5) | 0.24% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 21/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field. | |
| Aplazada | Alta (7.5) | 0.42% | — | Contact Form 7AI | 19/8/2026 | 20/8/2026 | Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | PAY With Contact Form 7AI | 19/8/2026 | 20/8/2026 | Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. | |
| Aplazada | Media (6.5) | 0.29% | — | Supsystic Contact FormAI | 18/8/2026 | 20/8/2026 | Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Supsystic Contact FormAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpzoom Forms Contact Form Plugin FOR GutenbergAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Contact Form 7 Paypal AND Stripe Add-onAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions. |