Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.37% | — | Mndpsingh287 Newsletter Popup | 16/5/2024 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 0.35% | — | Mndpsingh287 Newsletter Popup | 16/5/2024 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack | |
| Analizada | Media (6.9) | 0.25% | — | Mndpsingh287 Newsletter Popup | 16/5/2024 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack | |
| Analizada | Media (6.1) | 0.39% | — | Mndpsingh287 Newsletter Popup | 16/5/2024 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins | |
| Aplazada | Alta (8.1) | 0.74% | — | XML Sitemap Google NewsAI | 14/5/2024 | 17/6/2026 | The XML Sitemap & Google News plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.8 via the 'feed' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those… | |
| Aplazada | Media (4.3) | 0.25% | — | Kibokolabs Arigato Autoresponder AND NewsletterAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter.This issue affects Arigato Autoresponder and Newsletter: from n/a through 2.7.2.3. | |
| Aplazada | Media (5.9) | 0.43% | — | Harknell Awsom News AnnouncementAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Harknell AWSOM News Announcement allows Stored XSS.This issue affects AWSOM News Announcement: from n/a through 1.6.0. | |
| Aplazada | Media (6.5) | 0.47% | — | Woocoomerce Aweber Newsletter SubscriptionAI | 2/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Kestrel WooCommerce AWeber Newsletter Subscription.This issue affects WooCommerce AWeber Newsletter Subscription: from n/a through 4.0.2. | |
| Aplazada | Crítica (9.8) | 0.68% | — | Webbax SupernewsletterAI | 30/4/2024 | 17/6/2026 | SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privileges via the Super Newsletter module in the product_search.php components. | |
| Aplazada | Media (6.5) | 0.34% | — | Themegrill ColornewsAI | 29/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGrill ColorNews allows Stored XSS.This issue affects ColorNews: from n/a through 1.2.6. | |
| Analizada | Media (4.5) | 0.51% | — | ENL Newsletter Plugin Project Enl-newsletter | 26/4/2024 | 17/6/2026 | The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin+ to perform SQL injection attacks | |
| Analizada | Media (5.7) | 0.28% | — | ENL Newsletter Plugin Project Enl-newsletter | 26/4/2024 | 17/6/2026 | The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary Campaigns via a CSRF attack | |
| Analizada | Media (5.4) | 0.21% | — | ENL Newsletter Plugin Project Enl-newsletter | 26/4/2024 | 17/6/2026 | The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |
| Aplazada | Crítica (9.1) | 0.60% | — | Tribulant NewslettersAI | 24/4/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.5. | |
| Aplazada | Alta (7.5) | 0.68% | — | NewslettersAI | 24/4/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a through 4.9.5. | |
| Aplazada | Media (4.3) | 0.20% | — | Themeinwp NewsxpressAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Themeinwp NewsXpress.This issue affects NewsXpress: from n/a through 1.0.7. | |
| Aplazada | Media (5.4) | 0.20% | — | Stefano Lissa AND THE Newsletter Team NewsletterAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stefano Lissa & The Newsletter Team Newsletter.This issue affects Newsletter: from n/a through 8.0.6. | |
| Analizada | Media (5.3) | 0.81% | — | Phpgurukul News Portal Project | 15/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul/itsourcecode News Portal 4.1. This issue affects some unknown processing of the file search.php. The manipulation of the argument searchtitle leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.77% | — | Phpgurukul News Portal Project | 15/4/2024 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.php. The manipulation of the argument posttitle/category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (7.5) | 0.53% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 10/4/2024 | 12/8/2026 | Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5. | |
| Modificada | Media (5.3) | 0.58% | — | Blazethemes Newsmatic | 9/4/2024 | 17/6/2026 | The Newsmatic theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.0 via the 'newsmatic_filter_posts_load_tab_content'. This makes it possible for unauthenticated attackers to view draft posts and post content. | |
| Aplazada | Alta (7.1) | 0.35% | — | Katz WEB Services INC Contact Form 7 NewsletterAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Katz Web Services, Inc. Contact Form 7 Newsletter allows Reflected XSS.This issue affects Contact Form 7 Newsletter: from n/a through 2.2. | |
| Aplazada | Media (4.3) | 0.20% | — | News WallAI | 29/3/2024 | 17/6/2026 | The News Wall plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the nwap_newslist_page() function. This makes it possible for unauthenticated attackers to update the plugin's settings and modify news… | |
| Modificada | Media (4.3) | 0.18% | — | Logicore Pocket News Generator | 29/3/2024 | 17/6/2026 | The Pocket News Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.0. This is due to missing or incorrect nonce validation on the option_page() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged… | |
| Modificada | Media (4.8) | 0.32% | — | Logicore Pocket News Generator | 29/3/2024 | 17/6/2026 | The Pocket News Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as "Consumer Key" and "Access Token" in all versions up to, and including, 0.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… |