Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
3270 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.15% | — | Leav Last Email Address ValidatorAI | 16/1/2026 | 17/6/2026 | The LEAV Last Email Address Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions <= 1.7.1. This is due to missing or incorrect nonce validation on the display_settings_page function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request… | |
| Aplazada | Media (6.5) | 0.34% | — | Mailerlite Woocommerce IntegrationAI | 16/1/2026 | 17/6/2026 | The MailerLite - WooCommerce integration plugin for WordPress is vulnerable to unauthorized data modification and deletion in all versions up to, and including, 3.1.3. This is due to missing capability checks on the resetIntegration() function. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (5.1) | 0.29% | — | MailhogAI | 13/1/2026 | 17/6/2026 | Mailhog 1.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through email attachments. Attackers can send crafted emails with XSS payloads to execute arbitrary API calls, including message deletion and browser manipulation. | |
| Analizada | Media (6.5) | 0.24% | — | Axllent Mailpit | 10/1/2026 | 17/6/2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.28.2, the Mailpit WebSocket server is configured to accept connections from any origin. This lack of Origin header validation introduces a Cross-Site WebSocket Hijacking (CSWSH) vulnerability. An attacker can host a malicious website that,… | |
| Analizada | Media (5.3) | 0.81% | 💥 Exploit | Axllent Mailpit | 8/1/2026 | 17/6/2026 | Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (SSRF) vulnerability in the /proxy endpoint, allowing attackers to make requests to internal network resources. The /proxy endpoint validates http:// and https:// schemes, but it does not block… | |
| Aplazada | Media (6.4) | 0.26% | — | QR Code FOR Woocommerce Order Emails PDF Invoices Packing SlipsAI | 7/1/2026 | 17/6/2026 | The QR Code for WooCommerce order emails, PDF invoices, packing slips plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 1.9.42 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Aplazada | Media (6.5) | 0.29% | — | EmailkitAI | 7/1/2026 | 17/6/2026 | The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.6.1. This is due to missing path validation in the create_template REST API endpoint where user-controlled input from the emailkit-editor-template parameter is passed directly to… | |
| Aplazada | Media (4.4) | 0.33% | — | Email Customizer FOR WoocommerceAI | 7/1/2026 | 17/6/2026 | The Email Customizer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email template content in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access,… | |
| Aplazada | Crítica (9.8) | 0.35% | — | Optional EmailAI | 7/1/2026 | 7/10/2026 | The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This is due to the plugin not restricting its 'random_password' filter to registration contexts, allowing the filter to affect password reset key generation. This makes it… | |
| Aplazada | Media (4.3) | 0.12% | — | Newsletter Email SubscribeAI | 7/1/2026 | 7/10/2026 | The Newsletter Email Subscribe plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4. This is due to incorrect nonce validation on the nels_settings_page function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request… | |
| Aplazada | Media (4.3) | 0.14% | — | Inkthemes WP Gmail SmtpAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in inkthemes WP Gmail SMTP wp-gmail-smtp allows Cross Site Request Forgery.This issue affects WP Gmail SMTP: from n/a through <= 1.0.7. | |
| Aplazada | Alta (7.1) | 0.11% | — | Zoho ZeptomailAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail Zoho ZeptoMail transmail allows Stored XSS.This issue affects Zoho ZeptoMail: from n/a through <= 3.3.1. | |
| Aplazada | Media (4.3) | 0.26% | — | Renzojohnson Contact-form-7-mailchimp-extensionAI | 30/12/2025 | 7/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Renzo Johnson contact-form-7-mailchimp-extension contact-form-7-mailchimp-extension allows Retrieve Embedded Sensitive Data.This issue affects contact-form-7-mailchimp-extension: from n/a through <= 0.9.68. | |
| Analizada | Crítica (10) | 86% | ⚠ Explotación activa💥 Exploit | Smartertools Smartermail | 29/12/2025 | 7/10/2026 | Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution. | |
| Aplazada | Baja (2) | 0.23% | — | Yourmaileyes MoocAI | 28/12/2025 | 7/10/2026 | A security flaw has been discovered in yourmaileyes MOOC up to 1.17. This affects the function subreview of the file mooc/controller/MainController.java of the component Submission Handler. Performing manipulation of the argument review results in cross site scripting. The attack can be initiated remotely. The exploit… | |
| Aplazada | Media (4.3) | 0.13% | — | Winwar WP Email CaptureAI | 24/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Cross Site Request Forgery.This issue affects WP Email Capture: from n/a through <= 3.12.5. | |
| Aplazada | Alta (8.5) | 0.13% | — | Persits Software AspemailAI | 19/12/2025 | 17/6/2026 | AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the Persits Software EmailAgent service. Attackers can exploit full write permissions in the BIN directory to replace the service executable and gain elevated system access. | |
| Aplazada | Media (6.5) | 0.21% | — | Getresponse Email Marketing FOR WordpressAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-official allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Email marketing for WordPress by GetResponse Official: from n/a through <= 1.5.3. | |
| Aplazada | Media (6.5) | 0.32% | — | Getresponse Email Marketing FOR WordpressAI | 18/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-official allows Retrieve Embedded Sensitive Data.This issue affects Email marketing for WordPress by GetResponse Official: from n/a through <= 1.5.3. | |
| Aplazada | Alta (7.1) | 0.22% | — | MailsterAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster mailster allows Reflected XSS.This issue affects Mailster: from n/a through < 4.1.14. | |
| Aplazada | Media (5.8) | 0.27% | — | Mkscripts Download After EmailAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download After Email: from n/a through 2.1.5-2.1.6. | |
| Aplazada | Media (6.5) | 0.44% | — | Codepeople Contact Form 7 EmailAI | 18/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.60. | |
| Modificada | Alta (7.5) | 0.56% | — | NodemailerRedhat Advanced Cluster Management FOR KubernetesRedhat Ceph StorageRedhat Developer HUB | 18/12/2025 | 7/10/2026 | A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser. | |
| Analizada | Media (6.1) | 27% | ⚠ Explotación activa💥 PoC | Roundcube Webmail | 18/12/2025 | 17/6/2026 | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. | |
| Analizada | Alta (7.5) | 0.28% | — | Roundcube Webmail | 18/12/2025 | 17/6/2026 | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer. |