Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.59% | — | Newstatpress Project Newstatpress | 24/6/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in NewStatPress Plugin 1.2.4. This issue affects some unknown processing. The manipulation leads to basic cross site scripting (Persistent). The attack may be initiated remotely. Upgrading to version 1.2.5 is able to address this issue. It is… | |
| Modificada | Media (4.8) | 0.59% | — | Thenewsletterplugin Newsletter | 20/6/2022 | 17/6/2026 | The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Thenewsletterplugin Newsletter | 13/6/2022 | 17/6/2026 | The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9… | |
| Modificada | Media (5.4) | 0.57% | — | Google-news-sitemap Project Google-news-sitemap | 6/5/2022 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress, attackers must have contributor or higher user role. | |
| Modificada | Alta (8.8) | 4.2% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 7/3/2022 | 17/6/2026 | The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place… | |
| Modificada | Media (4.3) | 0.47% | — | Ec-cube E-mail Newsletter Management | 24/2/2022 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in EC-CUBE plugin 'Mail Magazine Management Plugin' ver4.0.0 to 4.1.1 (for EC-CUBE 4 series) and ver1.0.0 to 1.0.4 (for EC-CUBE 3 series) allows a remote unauthenticated attacker to hijack the authentication of an administrator via a specially crafted page, and Mail… | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (6.1) | 1.5% | 💥 Exploit | Newstatpress Project Newstatpress | 14/2/2022 | 17/6/2026 | The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Media (6.1) | 0.80% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 14/2/2022 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Media (6.1) | 0.81% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 24/1/2022 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Alta (7.1) | 1.1% | — | Nextcloud News | 30/11/2021 | 17/6/2026 | nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud News for Android app has a security issue by which a malicious application installed on the same device can send it an arbitrary Intent that gets reflected back, unintentionally giving read and write… | |
| Modificada | Media (6.1) | 0.64% | — | Sourcecodester News247 CMS | 28/10/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in Sourcecodester News247 CMS 1.0 via the search function in articles. | |
| Modificada | Media (5.9) | 1.8% | — | Phpgurukul News Portal | 27/10/2021 | 17/6/2026 | SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap… | |
| Modificada | Media (5.4) | 0.58% | — | Newsoftwares Folder Lock | 22/10/2021 | 17/6/2026 | Folder Lock v3.4.5 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Create Folder function under the 'create' module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload as a path or folder name. | |
| Modificada | Alta (8.8) | 1.7% | — | Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+39 | 11/10/2021 | 17/6/2026 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the… | |
| Modificada | Media (6.1) | 0.90% | — | Keszites Simple Popup Newsletter | 16/8/2021 | 17/6/2026 | The Simple Popup Newsletter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/simple-popup-newsletter.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.7. | |
| Modificada | Crítica (9.8) | 1.00% | — | Newsletter Project Newsletter | 13/8/2021 | 17/6/2026 | The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection. | |
| Modificada | Alta (7.2) | 0.67% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications. | |
| Modificada | Media (5.3) | 0.80% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data. | |
| Modificada | Media (6.1) | 0.59% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS. | |
| Modificada | Crítica (9.8) | 1.00% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection. | |
| Modificada | Alta (8.8) | 1.8% | — | Newsone CMS Project Newsone CMS | 11/8/2021 | 17/6/2026 | An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers to webshell and execute arbitrary commands. | |
| Modificada | Media (6.1) | 1.2% | — | Tagdiv Newsmag | 9/8/2021 | 17/6/2026 | The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability. | |
| Modificada | Alta (8.8) | 0.70% | — | Sola-newsletters Project Sola-newsletters | 5/8/2021 | 17/6/2026 | The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.23. | |
| Modificada | Alta (8.8) | 0.56% | — | Ipdgroup Newsplugin | 5/8/2021 | 17/6/2026 | The NewsPlugin WordPress plugin is vulnerable to Cross-Site Request Forgery via the handle_save_style function found in the ~/news-plugin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.18. |