Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
90 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.1% | — | Tribulant Newsletters | 22/8/2019 | 17/6/2026 | The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. | |
| Modificada | Alta (8.8) | 3.7% | — | Tribulant Newsletters | 15/8/2019 | 17/6/2026 | wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value. | |
| Modificada | Media (5.4) | 1.0% | — | Tribulant Newsletters | 9/8/2019 | 17/6/2026 | The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter. | |
| Modificada | Media (6.1) | 1.3% | — | Icegram Email Subscribers & Newsletters | 28/7/2019 | 17/6/2026 | An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin/admin-ajax.php POST parameter. | |
| Modificada | Crítica (9.8) | 3.7% | — | Icegram Email Subscribers & Newsletters | 19/7/2019 | 17/6/2026 | A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. | |
| Modificada | Media (6.1) | 1.2% | — | Email Subscribers & Newsletters Project Email Subscribers & Newsletters | 26/6/2018 | 17/6/2026 | Cross-site scripting vulnerability in Email Subscribers & Newsletters versions prior to 3.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.2% | — | Icegram Email Subscribers & Newsletters | 26/1/2018 | 17/6/2026 | An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading of a CSV data file with all subscriber data. | |
| Modificada | Media (6.1) | 1.4% | — | E-goi Smart Marketing SMS AND Newsletters Forms | 1/1/2018 | 17/6/2026 | The E-goi Smart Marketing SMS and Newsletters Forms plugin before 2.0.0 for WordPress has XSS via the admin/partials/custom/egoi-for-wp-form_egoi.php url parameter. | |
| Modificada | Media (6.8) | 1.1% | — | Mailpoet Newsletters | 26/8/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Alta (7.5) | 1.7% | — | Mailpoet Newsletters | 27/7/2014 | 17/6/2026 | Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors. | |
| Modificada | Alta (7.5) | 61% | 💥 Exploit | Mailpoet Newsletters | 27/7/2014 | 17/6/2026 | The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/. | |
| Modificada | Media (4.3) | 1.6% | — | Envialosimple Email Marketing Y Newsletters | 2/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in paginas/vista-previa-form.php in the EnvialoSimple: Email Marketing and Newsletters (envialosimple-email-marketing-y-newsletters-gratis) plugin before 1.98 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) FormID or (2)… | |
| Modificada | Media (6.5) | 4.3% | 💥 Exploit | Wysija Newsletters Project Wysija Newsletters | 24/3/2014 | 16/6/2026 | Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated… | |
| Modificada | Media (6.8) | 2.4% | 💥 Exploit | PHP Multiple Newsletters | 15/12/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter. | |
| Modificada | Media (4.3) | 3.4% | 💥 Exploit | Phpmultiplenewsletters | 15/12/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. |