Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
896 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.34% | — | Print PDF Email BY PrintfriendlyAI | 11/7/2026 | 13/7/2026 | The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and including, 5.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.1) | 0.16% | — | Samsung EmailAI | 10/7/2026 | 10/7/2026 | Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files within the application sandbox. | |
| Aplazada | Media (6.1) | 0.36% | — | Brevo Newsletter Smtp Email Marketing Subscribe FormsAI | 10/7/2026 | 10/7/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.47% | — | Blog Dash Email SubscribersAI | 2/7/2026 | 2/7/2026 | The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This… | |
| Aplazada | Media (5.4) | 0.29% | — | Omnisend Email Marketing FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Siteground Email MarketingAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wedevs WemailAI | 26/6/2026 | 18/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs weMail wemail allows Reflected XSS.This issue affects weMail: from n/a through 2.1.2. | |
| Aplazada | Alta (8.8) | 0.51% | — | Email Address Encoder Email Encoder PremiumAITillkruss Email Address EncoderAI | 25/6/2026 | 25/6/2026 | The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks | |
| Aplazada | Alta (7.2) | 0.36% | — | Email Javascript CloakAI | 24/6/2026 | 25/6/2026 | The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to, and including, 1.03 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.28% | — | Wedevs WemailAI | 17/6/2026 | 17/6/2026 | The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver… | |
| Aplazada | Alta (7.5) | 0.48% | — | Omnisend Email Marketing FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Speakout Email PetitionsAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions. | |
| Analizada | Alta (8.8) | 0.51% | — | Jenkins Email Extension | 27/5/2026 | 17/6/2026 | Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary… | |
| Aplazada | Media (6.4) | 0.32% | — | MY Email ShortcodeAI | 27/5/2026 | 17/6/2026 | The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode attribute in the 'my-email' shortcode in all versions up to, and including, 0.91 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.1) | 0.27% | — | Email EncoderAI | 20/5/2026 | 24/7/2026 | The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unauthenticated attackers to perform Stored XSS attacks | |
| Aplazada | Alta (7.5) | 0.75% | — | Nodemailer Smtp ServerAI | 15/5/2026 | 17/6/2026 | An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components | |
| Aplazada | Media (5.8) | 0.24% | — | Premailer CSS ParserAI | 14/5/2026 | 17/6/2026 | css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via HTTPS. The connection is established with OpenSSL::SSL::VERIFY_NONE, meaning any HTTPS… | |
| Aplazada | Media (5.1) | 0.19% | — | Contact Form TO EmailAI | 10/5/2026 | 25/7/2026 | Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name field. Attackers can craft form names containing JavaScript code that executes when other logged-in users access the form… | |
| Aplazada | Media (6.9) | 0.54% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information. | |
| Aplazada | Alta (8.3) | 0.73% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new GINA UI because an endpoint accepts attacker-controlled template, allowing remote attackers to execute arbitrary template expressions and potentially achieve remote code execution depending on the… | |
| Aplazada | Crítica (9.3) | 0.73% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes attacker-controlled input from a parameter to Perl's eval. | |
| Aplazada | Alta (8.8) | 0.54% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows remote attackers to read arbitrary local files and trigger deletion of files in the targeted directory with the privileges of the api.app… | |
| Aplazada | Crítica (9.2) | 0.76% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow unauthenticated remote attackers to execute code via a crafted serialized object. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new GINA UI, allowing unauthenticated remote attackers to access functionality that should require a valid session. | |
| Pendiente de análisis | Media (4.3) | 0.13% | — | Cisco Enterprise Chat AND EmailAI | 6/5/2026 | 17/6/2026 | A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct browser-based attacks. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Agent. |