Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.37% | — | Pluginops Mailchimp Subscribe Form | 28/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps MailChimp Subscribe Form plugin <= 4.0.9.1 versions. | |
| Modificada | Media (6.1) | 0.56% | — | Yikesinc Easy Forms FOR Mailchimp | 24/4/2023 | 17/6/2026 | The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (5.4) | 0.53% | — | Yikesinc Easy Forms FOR Mailchimp | 17/4/2023 | 17/6/2026 | The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.57% | — | Yikesplugins Easy Forms FOR Mailchimp | 12/12/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in yikes-inc-easy-mailchimp-extender Plugin up to 6.8.5. This affects an unknown part of the file admin/partials/ajax/add_field_to_form.php. The manipulation of the argument field_name/merge_tag/field_type/list_id leads to cross site scripting. It is possible to… | |
| Modificada | Baja (2.7) | 0.77% | — | Mailchimp FOR Woocommerce | 29/8/2022 | 17/6/2026 | The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example | |
| Modificada | Media (4.3) | 0.71% | — | Mailchimp FOR Woocommerce | 29/8/2022 | 17/6/2026 | The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for… | |
| Analizada | Media (4.8) | 0.52% | — | Ibericode Mailchimp FOR Wordpress | 20/5/2022 | 17/6/2026 | Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress. | |
| Modificada | Media (6.1) | 1.1% | — | Yikesinc Easy Forms FOR Mailchimp | 24/1/2022 | 17/6/2026 | The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Media (5.4) | 0.83% | — | Ilch CMS | 29/3/2021 | 17/6/2026 | An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login. | |
| Modificada | Media (6.1) | 0.70% | — | Ilch CMS | 19/3/2020 | 17/6/2026 | ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter. | |
| Modificada | Media (6.1) | 0.70% | — | Ilch CMS | 19/3/2020 | 17/6/2026 | ilchCMS 2.1.23 allows XSS via the index.php/partner/index Name parameter. | |
| Modificada | Media (6.1) | 0.69% | — | Ilch CMS | 19/3/2020 | 17/6/2026 | ilchCMS 2.1.23 allows XSS via the index.php/partner/index Link parameter. | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Alta (7.2) | 4.4% | — | Ilch CMS | 30/9/2019 | 17/6/2026 | Ilch 2.1.22 allows remote code execution because php is listed under "Allowed files" on the index.php/admin/media/settings/index page. | |
| Modificada | Media (4.8) | 0.68% | — | Ilch CMS | 30/9/2019 | 17/6/2026 | Ilch 2.1.22 allows stored XSS via the title, text, or email id to the Jobs Tab. | |
| Modificada | Media (6.1) | 0.91% | — | Ibericode Mailchimp FOR Wordpress | 22/8/2019 | 17/6/2026 | The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg. | |
| Modificada | Crítica (9.8) | 2.2% | — | Yikesinc Easy Forms FOR Mailchimp | 22/8/2019 | 17/6/2026 | The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field. | |
| Modificada | Media (6.1) | 0.92% | — | Ibericode Mailchimp FOR Wordpress | 13/8/2019 | 17/6/2026 | The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page. | |
| Modificada | Baja (2.1) | 1.4% | — | Thinkshout Mailchimp | 18/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the MailChimp Signup submodule in the MailChimp module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "administer mailchimp" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 0.64% | — | Ilch CMS | 25/2/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Ilch CMS allows remote attackers to hijack the authentication of administrators for requests that add a value to a profile field via a profilefields request to admin.php. | |
| Modificada | Media (4.3) | 1.9% | — | Easy Mailchimp Forms Plugin | 26/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Easy MailChimp Forms plugin 3.0 through 5.0.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the update_options action to wp-admin/admin-ajax.php. | |
| Modificada | Media (4.3) | 3.3% | 💥 Exploit | Ilch CMS | 9/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the text parameter to index.php/guestbook/index/newentry. | |
| Modificada | Media (4.3) | 1.2% | — | Thinkshout Mailchimp | 3/12/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the MailChimp module 7.x-2.x before 7.x-2.7 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) a predictable "webhook URL key" and (2) improper sanitization of "Webhook variables from POST requests." | |
| Modificada | Alta (7.5) | 1.2% | — | Ilch.de Ilchclan | 23/2/2006 | 16/6/2026 | SQL injection vulnerability in include/includes/user/login.php in ilchClan before 1.05g allows remote attackers to execute arbitrary SQL commands via the login_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Ilch.de Ilchclan | 23/2/2006 | 16/6/2026 | SQL injection vulnerability in the forum module of ilchClan 1.05g and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter, when creating a newpost. |