Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.8)0.12%—NewslettersAI29/8/202631/8/2026
The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions such as adding and deleting subscribers and sending emails, when the optional API…
AplazadaMedia (6.5)0.29%—Simple NewsletterAI26/8/202626/8/2026
The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that subscriber's stored details, allowing unauthenticated users to disclose a subscriber's personal data along with the key that authorises changes to their record.
AplazadaMedia (4.3)0.39%—NewslettersAI25/8/202628/9/2026
The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to send…
AplazadaMedia (6.9)0.34%—Cybertutor NewsiteserverAI24/8/202626/8/2026
NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school.
AplazadaMedia (5.1)0.23%—Cybertutor NewsiteserverAI24/8/202626/8/2026
NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting.
AplazadaAlta (7.1)0.25%—NewsletterAI19/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.
AplazadaMedia (6.5)0.22%—Acymailing Smtp NewsletterAI13/8/202614/8/2026
Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions.
AplazadaMedia (6.5)0.34%—Acymailing Smtp NewsletterAI13/8/202614/8/2026
Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.
AplazadaMedia (4.8)0.36%—NewslettersAI8/8/202626/8/2026
The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when the optional API has been enabled.
AplazadaAlta (8.1)0.45%—NewslettersAI8/8/202626/8/2026
The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.
AplazadaAlta (8.2)0.73%💥 ExploitNewslettersAI6/8/202626/8/2026
The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts.
AplazadaMedia (6.4)0.35%—Sendpulse Email Marketing NewsletterAI1/8/202612/8/2026
The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
AplazadaMedia (6.1)0.27%—NewstatpressAI31/7/202626/8/2026
The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and later outputting it in one of its widgets, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against users viewing the affected…
AplazadaMedia (6.4)0.35%—Newsletters LiteAI29/7/202630/7/2026
The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletters_post_thumbnail) shortcodes in versions up to and including 4.15. This is due to insufficient input sanitization and output escaping in the post_thumbnail() method in…
AplazadaMedia (6.4)0.35%—Newsletters LiteAI29/7/202630/7/2026
The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode in versions up to and including 4.15. This is due to insufficient input sanitization and output escaping in the posts_single() function which propagates the…
AplazadaMedia (6.1)0.25%—Thewp Digital Solutions News ThemeAI28/7/202628/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS. This issue affects News Theme V8: through 16.06.2026.
AplazadaAlta (8.1)0.55%—NewslettersAI14/7/202614/7/2026
The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress plugin before 4.15, write arbitrary files and…
AplazadaMedia (6.4)0.44%—News KIT Addons FOR ElementorAI14/7/202614/7/2026
The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.5)0.51%—Saurabhsharma Newsplus ShortcodesAIPHPAI13/7/202613/7/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortcodes newsplus-shortcodes allows PHP Local File Inclusion.This issue affects NewsPlus Shortcodes: from n/a through <= 4.2.0.
AplazadaAlta (7.1)0.25%—Acymailing Newsletter Team Acymailing Smtp NewsletterAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.
AplazadaAlta (7.1)0.32%—Acymailing Smtp NewsletterAI13/7/202613/7/2026
Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.1.
AplazadaCrítica (9.3)0.40%—Acymailing Smtp NewsletterAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.
AplazadaAlta (7.1)0.25%—Tribulant Software NewslettersAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through <= 4.14.
AplazadaMedia (6.1)0.36%—Brevo Newsletter Smtp Email Marketing Subscribe FormsAI10/7/202610/7/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (8.1)0.35%—Newsletters SubscribersAI26/6/202626/6/2026
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
Orbitaley — Vulnerabilidades