Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.56% | — | Yikesinc Easy Forms FOR Mailchimp | 24/4/2023 | 17/6/2026 | The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (5.4) | 0.53% | — | Yikesinc Easy Forms FOR Mailchimp | 17/4/2023 | 17/6/2026 | The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.57% | — | Yikesplugins Easy Forms FOR Mailchimp | 12/12/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in yikes-inc-easy-mailchimp-extender Plugin up to 6.8.5. This affects an unknown part of the file admin/partials/ajax/add_field_to_form.php. The manipulation of the argument field_name/merge_tag/field_type/list_id leads to cross site scripting. It is possible to… | |
| Modificada | Baja (2.7) | 0.77% | — | Mailchimp FOR Woocommerce | 29/8/2022 | 17/6/2026 | The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example | |
| Modificada | Media (4.3) | 0.71% | — | Mailchimp FOR Woocommerce | 29/8/2022 | 17/6/2026 | The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for… | |
| Analizada | Media (4.8) | 0.52% | — | Ibericode Mailchimp FOR Wordpress | 20/5/2022 | 17/6/2026 | Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress. | |
| Modificada | Media (6.1) | 1.1% | — | Yikesinc Easy Forms FOR Mailchimp | 24/1/2022 | 17/6/2026 | The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Media (6.1) | 0.91% | — | Ibericode Mailchimp FOR Wordpress | 22/8/2019 | 17/6/2026 | The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg. | |
| Modificada | Crítica (9.8) | 2.2% | — | Yikesinc Easy Forms FOR Mailchimp | 22/8/2019 | 17/6/2026 | The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field. | |
| Modificada | Media (6.1) | 0.92% | — | Ibericode Mailchimp FOR Wordpress | 13/8/2019 | 17/6/2026 | The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page. | |
| Modificada | Baja (2.1) | 1.4% | — | Thinkshout Mailchimp | 18/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the MailChimp Signup submodule in the MailChimp module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "administer mailchimp" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.9% | — | Easy Mailchimp Forms Plugin | 26/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Easy MailChimp Forms plugin 3.0 through 5.0.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the update_options action to wp-admin/admin-ajax.php. | |
| Modificada | Media (4.3) | 1.2% | — | Thinkshout Mailchimp | 3/12/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the MailChimp module 7.x-2.x before 7.x-2.7 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) a predictable "webhook URL key" and (2) improper sanitization of "Webhook variables from POST requests." |