Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
90 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Icegram Email Subscribers & Newsletters | 2/7/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of… | |
| Aplazada | Crítica (9.3) | 0.54% | — | Icegram Email Subscribers AND NewslettersAI | 26/6/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25. | |
| Modificada | Alta (8.8) | 0.23% | — | Tribulant Newsletters | 21/6/2024 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7. | |
| Modificada | Crítica (9.8) | 0.39% | — | Icegram Email Subscribers & Newsletters | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13. | |
| Modificada | Media (6.1) | 0.29% | — | Tribulant Newsletters | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS.This issue affects Newsletters: from n/a through 4.9.5. | |
| Modificada | Crítica (9.8) | 10% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 5/6/2024 | 17/6/2026 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Crítica (9.1) | 0.60% | — | Tribulant NewslettersAI | 24/4/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.5. | |
| Aplazada | Alta (7.5) | 0.68% | — | NewslettersAI | 24/4/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a through 4.9.5. | |
| Aplazada | Alta (7.1) | 0.39% | — | Icegram Email Subscribers AND NewslettersAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11. | |
| Modificada | Alta (7.2) | 0.96% | — | Tribulant Newsletters | 16/1/2024 | 17/6/2026 | The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server. | |
| Modificada | Alta (8.8) | 0.30% | — | Tribulant Newsletters | 10/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions. | |
| Modificada | Alta (8.8) | 0.76% | — | Icegram Email Subscribers & Newsletters | 12/12/2022 | 17/6/2026 | The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber | |
| Modificada | Alta (8.8) | 4.2% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 7/3/2022 | 17/6/2026 | The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place… | |
| Modificada | Alta (8.8) | 0.70% | — | Sola-newsletters Project Sola-newsletters | 5/8/2021 | 17/6/2026 | The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.23. | |
| Modificada | Media (6.1) | 0.75% | — | Ec-cube Email Newsletters Management | 22/6/2021 | 17/6/2026 | Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform a specific operation. | |
| Modificada | Media (5.3) | 1.6% | — | Icegram Email Subscribers & Newsletters | 10/9/2020 | 17/6/2026 | Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing. | |
| Modificada | Media (4.9) | 2.0% | — | Icegram Email Subscribers & Newsletters | 17/7/2020 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields. | |
| Modificada | Media (6.5) | 0.92% | — | Icegram Email Subscribers & Newsletters | 17/7/2020 | 17/6/2026 | Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link. | |
| Modificada | Crítica (9.8) | 85% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 8/1/2020 | 17/6/2026 | There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability). | |
| Modificada | Media (5.3) | 71% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure. | |
| Modificada | Media (6.3) | 0.97% | — | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns. | |
| Modificada | Media (5.3) | 1.2% | — | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request. | |
| Modificada | Media (5.4) | 0.56% | — | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings. | |
| Modificada | Media (4.3) | 1.0% | — | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to… | |
| Modificada | Media (5.3) | 0.95% | — | Mailpoet Newsletters | 6/11/2019 | 17/6/2026 | An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks. |