Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

75 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.37%—Pluginops Mailchimp Subscribe Form28/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps MailChimp Subscribe Form plugin <= 4.0.9.1 versions.
ModificadaMedia (6.1)0.56%—Yikesinc Easy Forms FOR Mailchimp24/4/202317/6/2026
The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (5.4)0.53%—Yikesinc Easy Forms FOR Mailchimp17/4/202317/6/2026
The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.1)0.57%—Yikesplugins Easy Forms FOR Mailchimp12/12/202217/6/2026
A vulnerability classified as problematic has been found in yikes-inc-easy-mailchimp-extender Plugin up to 6.8.5. This affects an unknown part of the file admin/partials/ajax/add_field_to_form.php. The manipulation of the argument field_name/merge_tag/field_type/list_id leads to cross site scripting. It is possible to…
ModificadaBaja (2.7)0.77%—Mailchimp FOR Woocommerce29/8/202217/6/2026
The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example
ModificadaMedia (4.3)0.71%—Mailchimp FOR Woocommerce29/8/202217/6/2026
The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for…
AnalizadaMedia (4.8)0.52%—Ibericode Mailchimp FOR Wordpress20/5/202217/6/2026
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress.
ModificadaMedia (6.1)1.1%—Yikesinc Easy Forms FOR Mailchimp24/1/202217/6/2026
The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
ModificadaMedia (5.4)0.83%—Ilch CMS29/3/202117/6/2026
An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login.
ModificadaMedia (6.1)0.70%—Ilch CMS19/3/202017/6/2026
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter.
ModificadaMedia (6.1)0.70%—Ilch CMS19/3/202017/6/2026
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Name parameter.
ModificadaMedia (6.1)0.69%—Ilch CMS19/3/202017/6/2026
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Link parameter.
ModificadaMedia (4.3)0.95%—Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+3431/10/201917/6/2026
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
ModificadaAlta (7.2)4.4%—Ilch CMS30/9/201917/6/2026
Ilch 2.1.22 allows remote code execution because php is listed under "Allowed files" on the index.php/admin/media/settings/index page.
ModificadaMedia (4.8)0.68%—Ilch CMS30/9/201917/6/2026
Ilch 2.1.22 allows stored XSS via the title, text, or email id to the Jobs Tab.
ModificadaMedia (6.1)0.91%—Ibericode Mailchimp FOR Wordpress22/8/201917/6/2026
The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.
ModificadaCrítica (9.8)2.2%—Yikesinc Easy Forms FOR Mailchimp22/8/201917/6/2026
The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.
ModificadaMedia (6.1)0.92%—Ibericode Mailchimp FOR Wordpress13/8/201917/6/2026
The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.
ModificadaBaja (2.1)1.4%—Thinkshout Mailchimp18/8/201517/6/2026
Cross-site scripting (XSS) vulnerability in the MailChimp Signup submodule in the MailChimp module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "administer mailchimp" permission to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)0.64%—Ilch CMS25/2/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in Ilch CMS allows remote attackers to hijack the authentication of administrators for requests that add a value to a profile field via a profilefields request to admin.php.
ModificadaMedia (4.3)1.9%—Easy Mailchimp Forms Plugin26/9/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Easy MailChimp Forms plugin 3.0 through 5.0.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the update_options action to wp-admin/admin-ajax.php.
ModificadaMedia (4.3)3.3%💥 ExploitIlch CMS9/3/201417/6/2026
Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the text parameter to index.php/guestbook/index/newentry.
ModificadaMedia (4.3)1.2%—Thinkshout Mailchimp3/12/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the MailChimp module 7.x-2.x before 7.x-2.7 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) a predictable "webhook URL key" and (2) improper sanitization of "Webhook variables from POST requests."
ModificadaAlta (7.5)1.2%—Ilch.de Ilchclan23/2/200616/6/2026
SQL injection vulnerability in include/includes/user/login.php in ilchClan before 1.05g allows remote attackers to execute arbitrary SQL commands via the login_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.3%💥 ExploitIlch.de Ilchclan23/2/200616/6/2026
SQL injection vulnerability in the forum module of ilchClan 1.05g and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter, when creating a newpost.
Orbitaley — Vulnerabilidades