Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

69 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.56%—Phplist1/7/202117/6/2026
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add a list" field under the "Import Emails" module.
ModificadaMedia (5.4)0.55%—Phplist1/7/202117/6/2026
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Configure categories" field under the "Categorise Lists" module.
ModificadaMedia (5.4)0.52%—Phplist1/7/202117/6/2026
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "List Description" field under the "Edit A List" module.
ModificadaMedia (5.4)0.55%—Phplist1/7/202117/6/2026
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Send test" field under the "Start or continue campaign" module.
ModificadaMedia (5.4)0.54%—Phplist1/7/202117/6/2026
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Edit Values" field under the "Configure Attributes" module.
ModificadaCrítica (9.8)1.2%—Phplist27/1/202117/6/2026
phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
ModificadaCrítica (9.8)1.8%—Phplist26/1/202117/6/2026
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
ModificadaAlta (7.2)1.5%—Phplist25/12/202017/6/2026
phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.
ModificadaMedia (5.4)0.75%—Phplist8/7/202017/6/2026
An issue was discovered in phpList through 3.5.4. An XSS vulnerability occurs within the Import Administrators section via upload of an edited text document. This also affects the Subscriber Lists section.
ModificadaAlta (8.8)1.2%—Phplist8/7/202017/6/2026
An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section.
ModificadaMedia (6.1)0.85%—Phplist4/6/202017/6/2026
phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.
ModificadaMedia (6.1)0.70%—Phplist4/5/202017/6/2026
phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.
ModificadaCrítica (9.8)5.9%💥 ExploitPhplist3/2/202017/6/2026
phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
ModificadaMedia (6.5)0.89%—Phplist Integration Project Phplist Integration21/4/201517/6/2026
SQL injection vulnerability in the PHPlist Integration Module before 6.x-1.7 for Drupal allows remote administrators to execute arbitrary SQL commands via unspecified vectors, related to the "phpList database."
ModificadaMedia (6.8)1.1%—Phplist5/5/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in the subscription page editor (spageedit) in phpList before 3.0.6 allows remote attackers to hijack the authentication of administrators via a request to admin/.
ModificadaMedia (4.3)1.6%💥 ExploitTincan Phplist1/10/201216/6/2026
Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the testtarget parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)2.9%💥 ExploitPhplist6/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in public_html/lists/admin/ in phpList before 2.10.18 allows remote attackers to inject arbitrary web script or HTML via the num parameter in a reconcileusers action.
ModificadaAlta (7.5)3.3%💥 ExploitPhplist6/9/201216/6/2026
SQL injection vulnerability in public_html/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbitrary SQL commands via the sortby parameter in a find action.
ModificadaMedia (4.3)2.1%💥 ExploitPhplist12/8/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) remote_user, (2) remote_database, (3) remote_userprefix, (4) remote_password, or (5) remote_prefix parameter to the import4 page; or the (6)…
ModificadaMedia (4.3)1.9%💥 ExploitPhplist12/8/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter; or the (2) footer, (3) status, or (4) testtarget parameter in the send page.
ModificadaAlta (7.5)1.1%💥 ExploitPhplist12/8/201216/6/2026
SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via the delete parameter to the editattributes page.
ModificadaBaja (2.6)1.9%💥 ExploitPhplist12/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in admin/index.php in phpList before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the unconfirmed parameter to the user page.
ModificadaMedia (4.3)0.76%💥 ExploitTincan Phplist13/4/201116/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue exists because of an incomplete fix for CVE-2011-0748.…
ModificadaMedia (6.8)1.5%💥 ExploitTincan Phplist13/4/201116/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) edit administrator accounts.
ModificadaMedia (6.8)0.72%—DrupalPaul Beaney Phplist24/11/200916/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) subscribing or (2) unsubscribing to mailing lists.
Orbitaley — Vulnerabilidades