Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
8569 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.4) | — | — | Havelsan SEF AI Chatbot PlatformAI | 2/10/2026 | 2/10/2026 | Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot Platform: before 2.1. | |
| Recibida | Alta (7.2) | — | — | Crocoblock JetformbuilderAI | 2/10/2026 | 2/10/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in all versions up to, and including, 3.6.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Recibida | Alta (7.2) | — | — | MW WP FormAI | 2/10/2026 | 2/10/2026 | The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 5.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Recibida | Alta (8.1) | — | — | Ninjaforms Ninja Forms File UploadsAI | 2/10/2026 | 2/10/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used… | |
| Recibida | Alta (7.2) | — | — | Ninjaforms Ninja FormsAI | 2/10/2026 | 2/10/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Recibida | Alta (8.8) | — | — | Super-forms Super FormsAI | 2/10/2026 | 2/10/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value… | |
| Recibida | Crítica (9.1) | — | — | Super-forms Super FormsAI | 2/10/2026 | 2/10/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Recibida | Alta (7.5) | — | — | Fasterxml Jackson-dataformats-binaryAI | 1/10/2026 | 1/10/2026 | The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongFieldName() grows its internal name buffer through an unconstrained… | |
| Recibida | Alta (7.5) | — | — | Fasterxml Jackson Dataformats BinaryAI | 1/10/2026 | 1/10/2026 | The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. CBORParser._decodeLongerName() decodes a definite-length property name with no length check, and… | |
| Aplazada | Media (5.3) | — | — | Wpexperts Contact Form 7 HoneypotAI | 1/10/2026 | 1/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WPExperts CF7 Apps contact-form-7-honeypot allows Retrieve Embedded Sensitive Data.This issue affects CF7 Apps: from n/a through 3.7.2. | |
| Aplazada | Media (6.5) | — | — | FluentformAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP ManageNinja LLC FluentForm fluentform allows Stored XSS.This issue affects FluentForm: from n/a through 6.2.14. | |
| Aplazada | Media (6.5) | — | — | Wpmet MetformAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Metform metform allows Stored XSS.This issue affects Metform: from n/a through 4.3.0. | |
| Aplazada | Media (5.3) | — | — | FluentformAI | 1/10/2026 | 1/10/2026 | Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14. | |
| Aplazada | Alta (7.2) | — | — | Incsub ForminatorAI | 1/10/2026 | 1/10/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | — | — | Bizessentials Business Essentials FOR Contact Form 7AI | 1/10/2026 | 1/10/2026 | The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (7.2) | — | — | 10web Form MakerAI | 1/10/2026 | 1/10/2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | — | — | Incsub ForminatorAI | 1/10/2026 | 1/10/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.1) | — | — | Super-forms Super FormsAI | 1/10/2026 | 1/10/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super… | |
| Aplazada | Media (4.7) | — | — | Calculated Fields FormAI | 1/10/2026 | 1/10/2026 | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (attacker-chosen name matching the form's url.<name> predefined value)' parameter in all versions up to, and including, 5.5.1.3 due… | |
| Aplazada | Media (6.1) | — | — | Calculatedfields Calculated Fields FormAI | 1/10/2026 | 1/10/2026 | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (any URL parameter consumed by the form's calculated equation)' parameter in all versions up to, and including, 5.5.1.3 due to… | |
| Aplazada | Crítica (9.8) | — | — | Super-forms Super FormsAI | 1/10/2026 | 1/10/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that… | |
| Aplazada | Baja (2.1) | — | — | Formtools Form ToolsAI | 1/10/2026 | 1/10/2026 | A flaw has been found in formtools.org Form Tools up to 3.1.1. Impacted is the function smart_fill of the file /global/code/actions.php of the component AJAX Endpoint. This manipulation of the argument url causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may… | |
| Aplazada | Baja (2.1) | — | — | Formtools Form ToolsAI | 1/10/2026 | 1/10/2026 | A vulnerability was detected in formtools.org Form Tools up to 3.1.1. This issue affects the function Files::uploadFile of the file global/code/actions.php of the component Ajax Handler. The manipulation results in unrestricted upload. It is possible to launch the attack remotely. The exploit is now public and may be… | |
| Aplazada | Baja (2.1) | — | — | Formtools Form ToolsAI | 1/10/2026 | 1/10/2026 | A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the component Client Settings. The manipulation of the argument page_titles leads to improper neutralization of… | |
| Pendiente de análisis | Alta (7.2) | 0.35% | — | Kiteworks Advanced FormsAI | 30/9/2026 | 1/10/2026 | A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions. |