Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
250 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.32% | — | Newsletter | 12/6/2024 | 17/6/2026 | The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PHP type juggling issue on the check_api_key function in all versions up to, and including, 2.4.5. This makes it possible for unauthenticated attackers to list, create or delete newsletter subscribers.… | |
| Modificada | Crítica (9.8) | 0.39% | — | Icegram Email Subscribers & Newsletters | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13. | |
| Modificada | Media (6.1) | 0.29% | — | Tribulant Newsletters | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS.This issue affects Newsletters: from n/a through 4.9.5. | |
| Modificada | Crítica (9.8) | 10% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 5/6/2024 | 17/6/2026 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Media (6.1) | 0.29% | — | Thenewsletterplugin Newsletter | 5/6/2024 | 17/6/2026 | The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Modificada | Media (6.1) | 0.29% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue allows Reflected XSS.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.77. | |
| Aplazada | Media (5.3) | 0.49% | — | Stefano Lissa AND THE Newsletter Team NewsletterAI | 17/5/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Stefano Lissa & The Newsletter Team Newsletter allows Functionality Bypass.This issue affects Newsletter: from n/a through 8.2.0. | |
| Analizada | Media (4.8) | 0.37% | — | Mndpsingh287 Newsletter Popup | 16/5/2024 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 0.35% | — | Mndpsingh287 Newsletter Popup | 16/5/2024 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack | |
| Analizada | Media (6.9) | 0.25% | — | Mndpsingh287 Newsletter Popup | 16/5/2024 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack | |
| Analizada | Media (6.1) | 0.39% | — | Mndpsingh287 Newsletter Popup | 16/5/2024 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins | |
| Aplazada | Media (4.3) | 0.25% | — | Kibokolabs Arigato Autoresponder AND NewsletterAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter.This issue affects Arigato Autoresponder and Newsletter: from n/a through 2.7.2.3. | |
| Aplazada | Media (6.5) | 0.47% | — | Woocoomerce Aweber Newsletter SubscriptionAI | 2/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Kestrel WooCommerce AWeber Newsletter Subscription.This issue affects WooCommerce AWeber Newsletter Subscription: from n/a through 4.0.2. | |
| Aplazada | Crítica (9.8) | 0.68% | — | Webbax SupernewsletterAI | 30/4/2024 | 17/6/2026 | SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privileges via the Super Newsletter module in the product_search.php components. | |
| Analizada | Media (4.5) | 0.51% | — | ENL Newsletter Plugin Project Enl-newsletter | 26/4/2024 | 17/6/2026 | The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin+ to perform SQL injection attacks | |
| Analizada | Media (5.7) | 0.28% | — | ENL Newsletter Plugin Project Enl-newsletter | 26/4/2024 | 17/6/2026 | The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary Campaigns via a CSRF attack | |
| Analizada | Media (5.4) | 0.21% | — | ENL Newsletter Plugin Project Enl-newsletter | 26/4/2024 | 17/6/2026 | The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |
| Aplazada | Crítica (9.1) | 0.60% | — | Tribulant NewslettersAI | 24/4/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.5. | |
| Aplazada | Alta (7.5) | 0.68% | — | NewslettersAI | 24/4/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a through 4.9.5. | |
| Aplazada | Media (5.4) | 0.20% | — | Stefano Lissa AND THE Newsletter Team NewsletterAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stefano Lissa & The Newsletter Team Newsletter.This issue affects Newsletter: from n/a through 8.0.6. | |
| Modificada | Alta (7.5) | 0.53% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 10/4/2024 | 12/8/2026 | Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5. | |
| Aplazada | Alta (7.1) | 0.35% | — | Katz WEB Services INC Contact Form 7 NewsletterAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Katz Web Services, Inc. Contact Form 7 Newsletter allows Reflected XSS.This issue affects Contact Form 7 Newsletter: from n/a through 2.2. | |
| Aplazada | Alta (7.1) | 0.39% | — | Icegram Email Subscribers AND NewslettersAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11. | |
| Modificada | Media (5.4) | 0.30% | — | Newsletter2go | 12/3/2024 | 17/6/2026 | The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 4.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject… | |
| Analizada | Alta (7.5) | 0.45% | — | Webbax Super Newsletter | 3/3/2024 | 17/6/2026 | An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to escalate privileges and obtain sensitive information. |