Vulnerabilities
Summary — last 7 days
New vulnerabilities2,713▼ 170 vs. last week
Critical / high1,244▼ 301 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 186 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.4) | 0.32% | — | Gatormail SmartformsAI | 1/11/2025 | 6/17/2026 | The GatorMail SmartForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gatormailsmartform' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modified | Medium (6.5) | 0.77% | — | K2 Smartforms | 5/24/2018 | 6/17/2026 | Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scripts URL. | |
| Modified | High (7.5) | 2.3% | — | Nintex K2 BlackpearlNintex K2 FOR SharepointNintex K2 Smartforms | 10/21/2015 | 6/17/2026 | SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote attackers to execute arbitrary SQL commands via the xml parameter. |