Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2744▲ 58 respecto a la semana anterior
Críticas / altas1456▲ 346 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)92▼ 421 respecto a la semana anterior
–

108 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.52%—Ninjaforms Ninja Forms File UploadsAI2/10/20262/10/2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used…
AplazadaAlta (7.2)0.29%—Ninjaforms Ninja FormsAI2/10/20262/10/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaAlta (7.1)0.18%—Ninjaforms Ninja FormsAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
AplazadaAlta (7.1)0.18%—Ninjaforms Ninja FormsAI23/9/202623/9/2026
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
AplazadaAlta (7.2)0.41%—Ninjaforms Ninja FormsAI22/9/202622/9/2026
Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.
AplazadaAlta (8.8)0.35%—Ninjaforms Ninja FormsAI22/9/202622/9/2026
The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the…
AplazadaAlta (7.5)0.30%—Ninjaforms Ninja FormsAI22/9/202622/9/2026
The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme,…
AplazadaMedia (6.4)0.26%—Ninja Forms Scheduled ExportsAI10/9/202611/9/2026
The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Parameters (interval, format, emailTo) in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.6)0.66%—Ninjaforms Ninja FormsAI9/9/20269/9/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP…
AplazadaMedia (4.8)0.24%—Ninjaforms Ninja FormsAI6/9/20268/9/2026
The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.
AplazadaMedia (4.3)0.16%—Ninja Forms Save ProgressAI5/9/20268/9/2026
The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaAlta (7.2)0.25%—Ninjaforms Ninja FormsAI5/9/20268/9/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaMedia (5.9)0.23%—Thedotstore Ninja FormsAI4/9/20268/9/2026
The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2…
AplazadaAlta (8.8)0.46%—Ninjaforms Ninja Forms - Layout & StylesAI2/9/20263/9/2026
Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
AplazadaMedia (4.8)0.24%—Ninjaforms Ninja FormsAI6/8/202626/8/2026
The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a…
AplazadaMedia (4.9)0.51%—Ninjaforms Ninja FormsAI24/7/202624/7/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaAlta (8.7)0.58%—Ninjaforms Ninja FormsAI21/7/202622/7/2026
Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment totals by submitting values that do not match any configured option in ListSelect or ListRadio fields.…
AplazadaMedia (6.9)0.49%—Ninjaforms Ninja FormsAI21/7/202623/7/2026
Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a…
AplazadaAlta (7.1)0.44%—Ninjaforms Ninja FormsAI21/7/202623/7/2026
Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding…
AplazadaAlta (8.4)0.44%—Ninjaforms Ninja FormsAI21/7/202621/7/2026
Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers…
AplazadaCrítica (9.3)0.54%—Ninjaforms Ninja FormsAI21/7/202621/7/2026
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the…
AplazadaMedia (6.4)0.26%—Ninja Forms Excel ExportAI17/7/202617/7/2026
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due to the save_filter() AJAX handler storing the raw $_POST['filter'] array into a WordPress option via update_option() without any capability check, nonce verification, or…
AplazadaMedia (4.3)0.66%—Ninja Forms Excel ExportAI17/7/202617/7/2026
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to write .xls/.xlsx files to arbitrary…
AplazadaMedia (4.3)0.28%—Ninja Forms Excel ExportAI17/7/202617/7/2026
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level…
AplazadaMedia (5.3)0.35%—Ninjaforms Ninja Forms File UploadsAI3/7/20266/7/2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read all plugin debug log…