Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
3270 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.17% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework Email Exceptions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv4$txtEmailDescription parameter to… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework IP Exceptions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv2$txtIPDescription parameter to… | |
| Analizada | Media (5.1) | 0.17% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the URI DNS Blocklist configuration page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_URIs parameter to /MailEssentials/pages/MailSecurity/uridnsblocklist.aspx, which is… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the IP DNS Blocklist configuration page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_IPs parameter to /MailEssentials/pages/MailSecurity/ipdnsblocklist.aspx, which is stored… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the IP Blocklist management page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$txtIPDescription parameter to /MailEssentials/pages/MailSecurity/ipblocklist.aspx, which is stored… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the POP2Exchange configuration endpoint. An authenticated user can supply HTML/JavaScript in the POP3 server login field within the JSON \"popServers\" payload to… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Perimeter SMTP Servers configuration page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv3$txtDescription parameter to… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Mail Monitoring rule creation endpoint. An authenticated user can supply HTML/JavaScript in the JSON \"name\" field to /MailEssentials/pages/MailSecurity/MailMonitoring.aspx/Save, which is stored and later rendered… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Anti-Spam Whitelist management interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$txtDescription parameter to /MailEssentials/pages/MailSecurity/Whitelist.aspx, which is… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Advanced Content Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$txtRuleName parameter to… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Attachment Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_RuleName parameter to… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Keyword Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_RuleName parameter to /MailEssentials/pages/MailSecurity/contentchecking.aspx,… | |
| Aplazada | Media (4.3) | 0.25% | — | Official-mailerlite-sign-up-formsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in MailerLite MailerLite official-mailerlite-sign-up-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailerLite: from n/a through <= 1.7.18. | |
| Aplazada | Alta (7.5) | 0.30% | — | Mail MintAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WPFunnels Mail Mint mail-mint allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Mail Mint: from n/a through <= 1.19.4. | |
| Aplazada | Media (4.4) | 0.25% | — | Postmarkapp Email IntegratorAI | 19/2/2026 | 17/6/2026 | The PostmarkApp Email Integrator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 2.4. This is due to insufficient input sanitization and output escaping on the pma_api_key and pma_sender_address parameters. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.38% | — | TWO Factor 2FA Authentication VIA EmailAI | 19/2/2026 | 17/6/2026 | The Two Factor (2FA) Authentication via Email plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 1.9.8. This is because the SS88_2FAVE::wp_login() method only enforces the 2FA requirement if the 'token' HTTP GET parameter is undefined, which makes it possible to… | |
| Aplazada | Media (4.3) | 0.14% | — | Mailchimp List Subscribe FormAI | 19/2/2026 | 17/6/2026 | The Mailchimp List Subscribe Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.0. This is due to missing or incorrect nonce validation on the mailchimp_sf_change_list_if_necessary() function. This makes it possible for unauthenticated attackers to change… | |
| Analizada | Crítica (9.3) | 0.89% | — | Tabslab Mailcarrier | 18/2/2026 | 17/6/2026 | MailCarrier 2.51 contains a buffer overflow vulnerability in the POP3 USER command that allows remote attackers to execute arbitrary code. Attackers can send a crafted oversized buffer to the POP3 service, overwriting memory and potentially gaining remote system access. | |
| Aplazada | Media (4.4) | 0.28% | — | YaymailAI | 18/2/2026 | 17/6/2026 | The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Shop Manager-level permissions and… | |
| Aplazada | Media (5.3) | 0.33% | — | YaymailAI | 18/2/2026 | 17/6/2026 | The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized license key deletion due to a missing authorization check on the `/yaymail-license/v1/license/delete` REST endpoint in versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with Shop… | |
| Aplazada | Baja (2.7) | 0.31% | — | YaymailAI | 18/2/2026 | 17/6/2026 | The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and activation due to missing capability checks on the 'yaymail_install_yaysmtp' AJAX action and `/yaymail/v1/addons/activate` REST endpoint in all versions up to, and including, 4.3.2. This makes it… | |
| Aplazada | Alta (7.2) | 0.44% | 💥 PoC | YaymailAI | 18/2/2026 | 17/6/2026 | The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the `yaymail_import_state` AJAX action in all versions up to, and including, 4.3.2. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.26% | — | EmailkitAI | 18/2/2026 | 17/6/2026 | The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'update_template_data' function in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Alta (7.2) | 0.38% | — | Smartertools SmartermailAI | 16/2/2026 | 17/6/2026 | SmarterTools SmarterMail before 9526 allows XSS via MAPI requests. | |
| Aplazada | Media (4.9) | 0.37% | — | Mail MintAI | 14/2/2026 | 17/6/2026 | The Mail Mint plugin for WordPress is vulnerable to blind SQL Injection via the 'forms', 'automation', 'email/templates', and 'contacts/import/tutorlms/map' API endpoints in all versions up to, and including, 1.19.2 . This is due to insufficient escaping on the user supplied 'order-by', 'order-type', and… |