Vulnerabilities
Summary — last 7 days
New vulnerabilities3,333▲ 343 vs. last week
Critical / high1,493▲ 121 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 117 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Received | Critical (9.8) | — | — | Super-forms Super FormsAI | 10/1/2026 | 10/1/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that… | |
| Deferred | High (7.5) | 0.50% | — | Super-forms Super FormsAI | 8/24/2026 | 8/24/2026 | Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions. | |
| Deferred | Critical (9.8) | 5.1% | — | Super-forms Super FormsAI | 7/10/2026 | 7/10/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only… | |
| Modified | Medium (6.1) | 0.31% | — | Super-forms Super Forms | 1/16/2024 | 6/17/2026 | The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zostala_rozwiazana parameter before outputting it back in an attribute via the super_language_switcher AJAX action, leading to a Reflected Cross-Site Scripting. The action is also lacking CSRF, making… |