Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3047▲ 440 respecto a la semana anterior
Críticas / altas1452▲ 212 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 151 respecto a la semana anterior
–

1170 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)——Super-forms Super FormsAI1/10/20261/10/2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super…
AplazadaCrítica (9.8)——Super-forms Super FormsAI1/10/20261/10/2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that…
Pendiente de análisisAlta (7.1)0.32%—Kiteworks Secure Data FormsAI30/9/20261/10/2026
A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an…
Pendiente de análisisAlta (7.5)0.45%—Kiteworks Secure Data FormsAI30/9/20261/10/2026
Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other…
Pendiente de análisisAlta (7.2)0.35%—Kiteworks Advanced FormsAI30/9/20261/10/2026
A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions.
Pendiente de análisisBaja (1.2)0.40%—Wikimedia Page FormsAI30/9/202630/9/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43.
AplazadaAlta (7.1)0.25%—HappyformsAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions.
AplazadaAlta (8.8)0.52%—Quantumcloud Conversational Forms FOR ChatbotAI30/9/202630/9/2026
Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.
AplazadaAlta (7.1)0.25%—Ninjaforms Ninja FormsAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
Pendiente de análisisCrítica (9.5)0.32%—Balbooa FormsAI29/9/202630/9/2026
Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component…
Pendiente de análisisAlta (8.9)0.37%—Balbooa FormsAI29/9/202630/9/2026
Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the…
Pendiente de análisisAlta (8.6)0.32%—Balbooa FormsAI29/9/202630/9/2026
Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A…
Pendiente de análisisMedia (6.9)0.37%—Balbooa FormsAI29/9/202630/9/2026
Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and display names are trusted directly, introducing potential cross-session claiming, metadata…
Pendiente de análisisMedia (6.9)0.29%—Balbooa FormsAI29/9/202630/9/2026
Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session…
AplazadaMedia (6.5)0.18%—Wpforms LiteAI28/9/202628/9/2026
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public…
AplazadaAlta (7.2)0.24%—Repeater Fields FOR Elementor FormsAI25/9/202625/9/2026
The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AplazadaMedia (6.1)0.27%—WpformsAI25/9/202625/9/2026
The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'page_title' POST Parameter via {page_title} Smart Tag in all versions up to, and including, 2.0.2 due to insufficient input sanitization and…
AplazadaMedia (6.8)0.18%—WpformsAI24/9/202624/9/2026
The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate subscription cancellation against payments created by other applications on the…
AplazadaAlta (7.1)0.18%—Ninjaforms Ninja FormsAI23/9/202623/9/2026
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
AplazadaAlta (8.5)0.22%—Mollie FormsAI23/9/202623/9/2026
Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.
AplazadaMedia (6.8)0.24%—Subscribe FormsAI23/9/202623/9/2026
The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who views a page embedding the…
AplazadaBaja (3.7)0.15%—Wpmudev Forminator FormsAI23/9/202623/9/2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail…
Pendiente de análisisCrítica (9.6)0.73%—Adobe Experience Manager Forms JEEAI22/9/202623/9/2026
Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope…
Pendiente de análisisAlta (8.7)0.81%—Adobe Experience Manager Forms JEEAI22/9/202623/9/2026
Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction.…
Pendiente de análisisCrítica (9.1)1.2%—Adobe Experience Manager Forms JEEAI22/9/202623/9/2026
Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user…