Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.39%—Kibokolabs Arigato Autoresponder AND Newsletter7/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1 versions.
ModificadaMedia (6.1)0.41%—Kibokolabs Arigato Autoresponder AND Newsletter7/4/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1.1 versions.
ModificadaMedia (5.4)0.38%—Kibokolabs Arigato Autoresponder AND Newsletter7/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1.1 versions.
ModificadaMedia (6.5)0.33%—Hasthemes WP News27/3/202317/6/2026
The WP News WordPress plugin through 1.1.9 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
ModificadaMedia (4.8)0.46%—Kibokolabs Arigato Autoresponder AND Newsletter27/2/202317/6/2026
The Arigato Autoresponder and Newsletter WordPress plugin before 2.1.7.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaCrítica (9.8)3.0%💥 PoCNewspaperclub PDF Info23/2/202317/6/2026
pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.
ModificadaBaja (3.7)0.85%—Mayurik Best Online News Portal12/2/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file check_availability.php. The manipulation of the argument username leads to exposure of sensitive information through data queries. The attack can be…
ModificadaCrítica (9.8)0.81%—Mayurik Best Online News Portal12/2/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. Affected is an unknown function of the component Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
ModificadaMedia (5.4)0.44%—Infornweb News & Blog Designer Pack30/1/202317/6/2026
The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
ModificadaMedia (5.4)0.53%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages16/1/202317/6/2026
The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as…
ModificadaCrítica (9.8)0.66%—Devnewsaggregator Project Devnewsaggregator5/1/202317/6/2026
A vulnerability was found in stevejagodzinski DevNewsAggregator. It has been rated as critical. Affected by this issue is the function getByName of the file php/data_access/RemoteHtmlContentDataAccess.php. The manipulation of the argument name leads to sql injection. The name of the patch is…
ModificadaMedia (6.5)0.33%—Moodle-block Sitenews Project Moodle-block Sitenews27/12/202217/6/2026
A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file block_sitenews.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.1 is able to address this…
ModificadaAlta (7.5)0.69%—FP Newsletter Project FP Newsletter14/12/202217/6/2026
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via unsubscribeAction operations.
ModificadaAlta (7.5)0.69%—FP Newsletter Project FP Newsletter14/12/202217/6/2026
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via createAction operations.
ModificadaAlta (7.5)0.62%—FP Newsletter Project FP Newsletter14/12/202217/6/2026
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Attackers can unsubscribe everyone via a series of modified subscription UIDs in deleteAction operations.
ModificadaCrítica (9.1)0.67%—FP Newsletter Project FP Newsletter14/12/202217/6/2026
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. There is a CAPTCHA bypass that can lead to subscribing many people.
ModificadaAlta (8.8)0.76%—Icegram Email Subscribers & Newsletters12/12/202217/6/2026
The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber
ModificadaMedia (4.8)0.42%—Storeapps News Announcement Scroll17/11/202217/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in News Announcement Scroll plugin <= 8.8.8 on WordPress.
ModificadaCrítica (9.8)3.8%💥 ExploitNewsmag Project NewsmagNewspaper Project NewspaperTagdiv Composer Project Tagdiv Composer14/11/202217/6/2026
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
ModificadaMedia (6.1)1.1%💥 ExploitTagdiv Newspaper31/10/202217/6/2026
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting.
ModificadaMedia (6.1)0.60%—Tagdiv Newspaper31/10/202217/6/2026
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting
ModificadaCrítica (9.8)1.2%—Newsletter Subscribe (popup + Regular Module) Project Newsletter Subscribe (popup + Regular Module)12/10/202217/6/2026
OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at index.php?route=extension/module/so_newletter_custom_popup/newsletter.
ModificadaMedia (4.8)1.0%—News247 News Magazine (cms) Project News247 News Magazine (cms)16/9/202217/6/2026
Cross Site Scripting (XSS vulnerability exists in )Sourcecodester News247 News Magazine (CMS) PHP 5.6 or higher and MySQL 5.7 or higher via the blog category name field
ModificadaCrítica (9.8)1.1%—Itechscripts News Portal Script16/7/202217/6/2026
A vulnerability was found in Itech News Portal 6.28. It has been classified as critical. Affected is an unknown function of the file /news-portal-script/information.php. The manipulation of the argument inf leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)1.5%—Newsletter Module Project Newsletter Module5/7/202217/6/2026
Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.
Orbitaley — Vulnerabilidades