Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.22% | — | Jegtheme Jnews Frontend SubmitAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews - Frontend Submit jnews-frontend-submit allows Reflected XSS.This issue affects JNews - Frontend Submit: from n/a through <= 11.0.0. | |
| Aplazada | Crítica (9.9) | 0.54% | — | Blazethemes News EventAI | 22/1/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects News Event: from n/a through <= 1.0.1. | |
| Aplazada | Media (4.3) | 0.12% | — | NewsletterAI | 20/1/2026 | 17/6/2026 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_action() function. This makes it possible for unauthenticated attackers to… | |
| Analizada | Baja (2.1) | 0.23% | — | Phpgurukul News Portal | 19/1/2026 | 17/6/2026 | A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. | |
| Modificada | Baja (2.1) | 0.34% | — | Phpgurukul News Portal | 19/1/2026 | 17/6/2026 | A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the component Add Sub-Admin Page. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Crítica (9.8) | 1.5% | 💥 PoC | News AND Blog Designer BundleAI | 14/1/2026 | 17/6/2026 | The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1 via the template parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in… | |
| Analizada | Crítica (9.8) | 0.59% | — | Phpgurukul News Portal | 13/1/2026 | 17/6/2026 | phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication. | |
| Analizada | Crítica (9.8) | 0.46% | — | Phpgurukul News Portal | 13/1/2026 | 17/6/2026 | phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php. | |
| Analizada | Crítica (9.1) | 0.45% | — | Phpgurukul News Portal | 13/1/2026 | 17/6/2026 | phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be deleted. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Tribulant Software NewslettersAI | 8/1/2026 | 7/10/2026 | Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11. | |
| Aplazada | Media (4.3) | 0.12% | — | Newsletter Email SubscribeAI | 7/1/2026 | 7/10/2026 | The Newsletter Email Subscribe plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4. This is due to incorrect nonce validation on the nels_settings_page function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request… | |
| Aplazada | Crítica (9.9) | 0.51% | — | Themify SidepaneAIThemify NewsyAIThemify FoloAIThemify EdminAI+5 | 6/1/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This issue affects… | |
| Aplazada | Media (6.5) | 0.16% | — | Tribulant Software NewslettersAI | 30/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Stored XSS.This issue affects Newsletters: from n/a through <= 4.12. | |
| Analizada | Baja (2) | 0.34% | — | Anirbandutta News-buzzCode-projects Content Management System | 29/12/2025 | 7/10/2026 | A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The exploit has… | |
| Aplazada | Alta (8.1) | 0.50% | — | Pencidesign PennewsAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign PenNews pennews allows PHP Local File Inclusion.This issue affects PenNews: from n/a through < 6.7.3. | |
| Aplazada | Alta (7.6) | 0.40% | — | Stefano Lissa NewsletterAI | 16/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stefano Lissa Newsletter newsletter allows Blind SQL Injection.This issue affects Newsletter: from n/a through <= 9.0.9. | |
| Aplazada | Media (4.3) | 0.26% | — | Sendpulse Email Marketing NewsletterAI | 16/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in SendPulse SendPulse Email Marketing Newsletter sendpulse-email-marketing-newsletter allows Retrieve Embedded Sensitive Data.This issue affects SendPulse Email Marketing Newsletter: from n/a through <= 2.2.1. | |
| Analizada | Media (5.3) | 0.58% | — | Anirbandutta9 News-buzz | 15/12/2025 | 17/6/2026 | SQL injection vulnerability in anirbandutta9 NEWS-BUZZ v.1.0 allows a remote attacker to execute arbitrary code via a crafted script. | |
| Aplazada | Media (6.4) | 0.23% | — | NewstatpressAI | 12/12/2025 | 17/6/2026 | The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode function in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.12% | — | Jegtheme Jnews PaywallAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in jegtheme JNews Paywall jnews-paywall allows Cross Site Request Forgery.This issue affects JNews Paywall: from n/a through < 12.0.1. | |
| Aplazada | Media (5.3) | 0.25% | — | Pencidesign PennewsAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in PenciDesign PenNews pennews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PenNews: from n/a through < 6.7.4. | |
| Aplazada | Media (6.5) | 0.20% | — | Jegtheme Jnews GalleryAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews Gallery jnews-gallery allows Stored XSS.This issue affects JNews Gallery: from n/a through < 12.0.1. | |
| Aplazada | Media (6.5) | 0.25% | — | Jegstudio Gutenverse NewsAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Jegstudio Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons gutenverse-news allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons: from n/a through <=… | |
| Aplazada | Media (6.4) | 0.23% | — | Cute News TickerAI | 6/12/2025 | 17/6/2026 | The Cute News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Media (6.1) | 0.25% | — | Nouri.sh NewsletterAI | 5/12/2025 | 17/6/2026 | The Nouri.sh Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 1.0.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… |