Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
54 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.28% | — | Wpmailster WP Mailster | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster wp-mailster allows Cross Site Request Forgery.This issue affects WP Mailster: from n/a through <= 1.8.17.0. | |
| Modificada | Crítica (9.8) | 0.47% | — | Wpmailster WP Mailster | 6/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in brandtoss WP Mailster wp-mailster allows Blind SQL Injection.This issue affects WP Mailster: from n/a through <= 1.8.16.0. | |
| Modificada | Crítica (9.8) | 0.58% | — | Wpmailster WP Mailster | 6/12/2024 | 17/6/2026 | Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through <= 1.8.16.0. | |
| Modificada | Alta (7.5) | 0.58% | — | Wpmailster WP Mailster | 6/12/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n/a through <= 1.8.16.0. | |
| Modificada | Alta (8.8) | 0.51% | — | Wpmailster WP Mailster | 6/12/2024 | 17/6/2026 | Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through <= 1.8.16.0. | |
| Analizada | Media (5.4) | 0.30% | — | Wpmailster WP Mailster | 3/12/2024 | 17/6/2026 | The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' shortcode in all versions up to, and including, 1.8.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.30% | — | Wpmailster WP Mailster | 28/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster wp-mailster allows Stored XSS.This issue affects WP Mailster: from n/a through <= 1.8.16.0. | |
| Aplazada | Alta (7.1) | 0.32% | — | Jamesward WP Mail CatcherAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JWardee WP Mail Catcher wp-mail-catcher allows Reflected XSS.This issue affects WP Mail Catcher: from n/a through <= 2.1.9. | |
| Aplazada | Baja (2.7) | 0.57% | — | Wpforms WP Mail SmtpAI | 20/7/2024 | 17/6/2026 | The WP Mail SMTP plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 4.0.1. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings. This makes it possible for authenticated attackers, with administrative-level access and… | |
| Aplazada | Media (4.3) | 0.21% | — | Jamesward WP Mail CatcherAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in James Ward WP Mail Catcher.This issue affects WP Mail Catcher: from n/a through 2.1.6. | |
| Modificada | Alta (8.8) | 0.61% | — | Wpvibes WP Mail LOG | 29/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WPVibes WP Mail Log.This issue affects WP Mail Log: from n/a through 1.1.2. | |
| Modificada | Alta (7.2) | 0.53% | — | Jamesward WP Mail Catcher | 28/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in James Ward Mail logging – WP Mail Catcher.This issue affects Mail logging – WP Mail Catcher: from n/a through 2.1.3. | |
| Modificada | Alta (8.8) | 11% | — | Wpvibes WP Mail LOG | 26/12/2023 | 17/6/2026 | The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor. | |
| Modificada | Alta (8.8) | 1.1% | — | Wpvibes WP Mail LOG | 26/12/2023 | 17/6/2026 | The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to upload PHP files, leading to remote code execution. | |
| Modificada | Media (6.5) | 0.71% | — | Wpvibes WP Mail LOG | 26/12/2023 | 17/6/2026 | The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file inclusion, and allowing an attacker to leak the contents of arbitrary files. | |
| Modificada | Alta (8.8) | 0.72% | — | Wpvibes WP Mail LOG | 26/12/2023 | 17/6/2026 | The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor. | |
| Modificada | Alta (7.6) | 0.50% | — | Wpvibes WP Mail LOG | 26/12/2023 | 17/6/2026 | The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users. | |
| Modificada | Media (5.4) | 0.48% | — | Ironikus WP Mailto Links | 20/10/2023 | 17/6/2026 | The WP Mailto Links – Protect Email Addresses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wpml_mailto' shortcode in versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Modificada | Media (5.3) | 0.51% | — | Wpforms WP Mail Smtp | 4/10/2023 | 17/6/2026 | The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_print_page function in versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to disclose potentially sensitive email information. | |
| Modificada | Media (6.1) | 0.46% | — | Wpvibes WP Mail LOG | 12/7/2023 | 17/6/2026 | The WP Mail Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (6.1) | 0.65% | — | Awesomemotive WP Mail Logging | 12/7/2023 | 17/6/2026 | The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (6.1) | 0.46% | — | Jamesward WP Mail Catcher | 12/7/2023 | 17/6/2026 | The WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Alta (8.8) | 0.26% | — | Wpvibes WP Mail LOG | 2/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions. | |
| Modificada | Alta (7.5) | 1.5% | — | Premierethemes LOG WP Mail | 13/6/2022 | 17/6/2026 | The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filenames, allowing any unauthenticated visitor to obtain potentially sensitive information like generated passwords. | |
| Modificada | Media (6.1) | 0.90% | — | Wpmailster WP Mailster | 21/10/2021 | 17/6/2026 | WP Mailster 1.6.18.0 allows XSS when a victim opens a mail server's details in the mst_servers page, for a crafted server_host, server_name, or connection_parameter parameter. |