Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.12% | — | NewslettersAI | 29/8/2026 | 31/8/2026 | The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions such as adding and deleting subscribers and sending emails, when the optional API… | |
| Aplazada | Media (6.5) | 0.29% | — | Simple NewsletterAI | 26/8/2026 | 26/8/2026 | The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that subscriber's stored details, allowing unauthenticated users to disclose a subscriber's personal data along with the key that authorises changes to their record. | |
| Aplazada | Media (4.3) | 0.39% | — | NewslettersAI | 25/8/2026 | 28/9/2026 | The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to send… | |
| Aplazada | Media (6.9) | 0.34% | — | Cybertutor NewsiteserverAI | 24/8/2026 | 26/8/2026 | NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school. | |
| Aplazada | Media (5.1) | 0.23% | — | Cybertutor NewsiteserverAI | 24/8/2026 | 26/8/2026 | NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting. | |
| Aplazada | Alta (7.1) | 0.25% | — | NewsletterAI | 19/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Acymailing Smtp NewsletterAI | 13/8/2026 | 14/8/2026 | Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Acymailing Smtp NewsletterAI | 13/8/2026 | 14/8/2026 | Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions. | |
| Aplazada | Media (4.8) | 0.36% | — | NewslettersAI | 8/8/2026 | 26/8/2026 | The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when the optional API has been enabled. | |
| Aplazada | Alta (8.1) | 0.45% | — | NewslettersAI | 8/8/2026 | 26/8/2026 | The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects. | |
| Aplazada | Alta (8.2) | 0.73% | 💥 Exploit | NewslettersAI | 6/8/2026 | 26/8/2026 | The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts. | |
| Aplazada | Media (6.4) | 0.35% | — | Sendpulse Email Marketing NewsletterAI | 1/8/2026 | 12/8/2026 | The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (6.1) | 0.27% | — | NewstatpressAI | 31/7/2026 | 26/8/2026 | The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and later outputting it in one of its widgets, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against users viewing the affected… | |
| Aplazada | Media (6.4) | 0.35% | — | Newsletters LiteAI | 29/7/2026 | 30/7/2026 | The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletters_post_thumbnail) shortcodes in versions up to and including 4.15. This is due to insufficient input sanitization and output escaping in the post_thumbnail() method in… | |
| Aplazada | Media (6.4) | 0.35% | — | Newsletters LiteAI | 29/7/2026 | 30/7/2026 | The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode in versions up to and including 4.15. This is due to insufficient input sanitization and output escaping in the posts_single() function which propagates the… | |
| Aplazada | Media (6.1) | 0.25% | — | Thewp Digital Solutions News ThemeAI | 28/7/2026 | 28/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS. This issue affects News Theme V8: through 16.06.2026. | |
| Aplazada | Alta (8.1) | 0.55% | — | NewslettersAI | 14/7/2026 | 14/7/2026 | The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress plugin before 4.15, write arbitrary files and… | |
| Aplazada | Media (6.4) | 0.44% | — | News KIT Addons FOR ElementorAI | 14/7/2026 | 14/7/2026 | The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.51% | — | Saurabhsharma Newsplus ShortcodesAIPHPAI | 13/7/2026 | 13/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortcodes newsplus-shortcodes allows PHP Local File Inclusion.This issue affects NewsPlus Shortcodes: from n/a through <= 4.2.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | Acymailing Newsletter Team Acymailing Smtp NewsletterAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0. | |
| Aplazada | Alta (7.1) | 0.32% | — | Acymailing Smtp NewsletterAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.1. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Acymailing Smtp NewsletterAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | Tribulant Software NewslettersAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through <= 4.14. | |
| Aplazada | Media (6.1) | 0.36% | — | Brevo Newsletter Smtp Email Marketing Subscribe FormsAI | 10/7/2026 | 10/7/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.1) | 0.35% | — | Newsletters SubscribersAI | 26/6/2026 | 26/6/2026 | newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions. |