Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
4598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Advanced Content Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$txtRuleName parameter to… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Attachment Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_RuleName parameter to… | |
| Analizada | Media (5.1) | 0.18% | — | GFI Mailessentials | 19/2/2026 | 17/6/2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Keyword Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_RuleName parameter to /MailEssentials/pages/MailSecurity/contentchecking.aspx,… | |
| Aplazada | Media (4.3) | 0.25% | — | Official-mailerlite-sign-up-formsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in MailerLite MailerLite official-mailerlite-sign-up-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailerLite: from n/a through <= 1.7.18. | |
| Aplazada | Alta (7.5) | 0.30% | — | Mail MintAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WPFunnels Mail Mint mail-mint allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Mail Mint: from n/a through <= 1.19.4. | |
| Aplazada | Media (4.4) | 0.25% | — | Postmarkapp Email IntegratorAI | 19/2/2026 | 17/6/2026 | The PostmarkApp Email Integrator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 2.4. This is due to insufficient input sanitization and output escaping on the pma_api_key and pma_sender_address parameters. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.38% | — | TWO Factor 2FA Authentication VIA EmailAI | 19/2/2026 | 17/6/2026 | The Two Factor (2FA) Authentication via Email plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 1.9.8. This is because the SS88_2FAVE::wp_login() method only enforces the 2FA requirement if the 'token' HTTP GET parameter is undefined, which makes it possible to… | |
| Aplazada | Media (4.3) | 0.14% | — | Mailchimp List Subscribe FormAI | 19/2/2026 | 17/6/2026 | The Mailchimp List Subscribe Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.0. This is due to missing or incorrect nonce validation on the mailchimp_sf_change_list_if_necessary() function. This makes it possible for unauthenticated attackers to change… | |
| Analizada | Crítica (9.3) | 0.89% | — | Tabslab Mailcarrier | 18/2/2026 | 17/6/2026 | MailCarrier 2.51 contains a buffer overflow vulnerability in the POP3 USER command that allows remote attackers to execute arbitrary code. Attackers can send a crafted oversized buffer to the POP3 service, overwriting memory and potentially gaining remote system access. | |
| Aplazada | Media (4.4) | 0.28% | — | YaymailAI | 18/2/2026 | 17/6/2026 | The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Shop Manager-level permissions and… | |
| Aplazada | Media (5.3) | 0.33% | — | YaymailAI | 18/2/2026 | 17/6/2026 | The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized license key deletion due to a missing authorization check on the `/yaymail-license/v1/license/delete` REST endpoint in versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with Shop… | |
| Aplazada | Baja (2.7) | 0.31% | — | YaymailAI | 18/2/2026 | 17/6/2026 | The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and activation due to missing capability checks on the 'yaymail_install_yaysmtp' AJAX action and `/yaymail/v1/addons/activate` REST endpoint in all versions up to, and including, 4.3.2. This makes it… | |
| Aplazada | Alta (7.2) | 0.44% | 💥 PoC | YaymailAI | 18/2/2026 | 17/6/2026 | The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the `yaymail_import_state` AJAX action in all versions up to, and including, 4.3.2. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.26% | — | EmailkitAI | 18/2/2026 | 17/6/2026 | The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'update_template_data' function in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Alta (7.2) | 0.38% | — | Smartertools SmartermailAI | 16/2/2026 | 17/6/2026 | SmarterTools SmarterMail before 9526 allows XSS via MAPI requests. | |
| Aplazada | Media (4.9) | 0.37% | — | Mail MintAI | 14/2/2026 | 17/6/2026 | The Mail Mint plugin for WordPress is vulnerable to blind SQL Injection via the 'forms', 'automation', 'email/templates', and 'contacts/import/tutorlms/map' API endpoints in all versions up to, and including, 1.19.2 . This is due to insufficient escaping on the user supplied 'order-by', 'order-type', and… | |
| Aplazada | Media (5.3) | 0.30% | — | Mailchimp CampaignsAI | 14/2/2026 | 17/6/2026 | The MailChimp Campaigns plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.2.4. This is due to missing capability checks on the `mailchimp_campaigns_manager_disconnect_app` function that is hooked to the AJAX action of the same name. This makes it possible for… | |
| Aplazada | Alta (8.1) | 0.50% | — | Magic Login Mail OR QR CodeAI | 14/2/2026 | 17/6/2026 | The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to the plugin storing the magic login QR code image with a predictable, static filename (QR_Code.png) in the publicly accessible WordPress uploads directory during the… | |
| Aplazada | Media (6.1) | 0.21% | — | Easy Voice MailAI | 14/2/2026 | 17/6/2026 | The Easy Voice Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Alta (8.5) | 0.16% | — | WorkgroupmailAI | 11/2/2026 | 17/6/2026 | WorkgroupMail 7.5.1 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup. | |
| Aplazada | Media (4.7) | 0.53% | — | Roundcube WebmailAI | 11/2/2026 | 17/6/2026 | Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled. | |
| Aplazada | Media (4.3) | 0.54% | 💥 PoC | Roundcube WebmailAI | 9/2/2026 | 17/6/2026 | Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage. | |
| Modificada | Crítica (9) | 0.29% | 💥 PoC | Axigen Mail Server | 5/2/2026 | 17/6/2026 | Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exist: (1) the log file name parameter in the Local Services Log page, (2) certificate file content in the SSL Certificates View Usage feature, and (3) the Certificate File… | |
| Modificada | Media (5.4) | 0.20% | — | Axigen Mail Server | 5/2/2026 | 17/6/2026 | Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter. Attackers can exploit this by deploying a multi-stage attack. In the first stage, a malicious JavaScript payload is injected into the timeFormat preference by exploiting a separate… | |
| Analizada | Alta (8.8) | 0.28% | 💥 PoC | Axigen Mail Server | 5/2/2026 | 17/6/2026 | Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface through improper handling of the _s (breadcrumb) parameter. The application accepts state-changing requests via the GET method and automatically processes base64-encoded… |