Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.59%—Newstatpress Project Newstatpress24/6/202217/6/2026
A vulnerability, which was classified as problematic, has been found in NewStatPress Plugin 1.2.4. This issue affects some unknown processing. The manipulation leads to basic cross site scripting (Persistent). The attack may be initiated remotely. Upgrading to version 1.2.5 is able to address this issue. It is…
ModificadaMedia (4.8)0.59%—Thenewsletterplugin Newsletter20/6/202217/6/2026
The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed
ModificadaMedia (6.1)1.9%💥 ExploitThenewsletterplugin Newsletter13/6/202217/6/2026
The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9…
ModificadaMedia (5.4)0.57%—Google-news-sitemap Project Google-news-sitemap6/5/202217/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress, attackers must have contributor or higher user role.
ModificadaAlta (8.8)4.2%💥 ExploitIcegram Email Subscribers & Newsletters7/3/202217/6/2026
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place…
ModificadaMedia (4.3)0.47%—Ec-cube E-mail Newsletter Management24/2/202217/6/2026
Cross-site request forgery (CSRF) vulnerability in EC-CUBE plugin 'Mail Magazine Management Plugin' ver4.0.0 to 4.1.1 (for EC-CUBE 4 series) and ver1.0.0 to 1.0.4 (for EC-CUBE 3 series) allows a remote unauthenticated attacker to hijack the authentication of an administrator via a specially crafted page, and Mail…
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaMedia (6.1)1.5%💥 ExploitNewstatpress Project Newstatpress14/2/202217/6/2026
The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
ModificadaMedia (6.1)0.80%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe14/2/202217/6/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
ModificadaMedia (6.1)0.81%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe24/1/202217/6/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
ModificadaAlta (7.1)1.1%—Nextcloud News30/11/202117/6/2026
nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud News for Android app has a security issue by which a malicious application installed on the same device can send it an arbitrary Intent that gets reflected back, unintentionally giving read and write…
ModificadaMedia (6.1)0.64%—Sourcecodester News247 CMS28/10/202117/6/2026
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester News247 CMS 1.0 via the search function in articles.
ModificadaMedia (5.9)1.8%—Phpgurukul News Portal27/10/202117/6/2026
SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap…
ModificadaMedia (5.4)0.58%—Newsoftwares Folder Lock22/10/202117/6/2026
Folder Lock v3.4.5 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Create Folder function under the 'create' module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload as a path or folder name.
ModificadaAlta (8.8)1.7%—Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+3911/10/202117/6/2026
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the…
ModificadaMedia (6.1)0.90%—Keszites Simple Popup Newsletter16/8/202117/6/2026
The Simple Popup Newsletter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/simple-popup-newsletter.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.7.
ModificadaCrítica (9.8)1.00%—Newsletter Project Newsletter13/8/202117/6/2026
The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.
ModificadaAlta (7.2)0.67%—Dated News Project Dated News13/8/202117/6/2026
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications.
ModificadaMedia (5.3)0.80%—Dated News Project Dated News13/8/202117/6/2026
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data.
ModificadaMedia (6.1)0.59%—Dated News Project Dated News13/8/202117/6/2026
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.
ModificadaCrítica (9.8)1.00%—Dated News Project Dated News13/8/202117/6/2026
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.
ModificadaAlta (8.8)1.8%—Newsone CMS Project Newsone CMS11/8/202117/6/2026
An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers to webshell and execute arbitrary commands.
ModificadaMedia (6.1)1.2%—Tagdiv Newsmag9/8/202117/6/2026
The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.
ModificadaAlta (8.8)0.70%—Sola-newsletters Project Sola-newsletters5/8/202117/6/2026
The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.23.
ModificadaAlta (8.8)0.56%—Ipdgroup Newsplugin5/8/202117/6/2026
The NewsPlugin WordPress plugin is vulnerable to Cross-Site Request Forgery via the handle_save_style function found in the ~/news-plugin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.18.
Orbitaley — Vulnerabilidades