Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

250 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.32%—Newsletter12/6/202417/6/2026
The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PHP type juggling issue on the check_api_key function in all versions up to, and including, 2.4.5. This makes it possible for unauthenticated attackers to list, create or delete newsletter subscribers.…
ModificadaCrítica (9.8)0.39%—Icegram Email Subscribers & Newsletters9/6/202417/6/2026
Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13.
ModificadaMedia (6.1)0.29%—Tribulant Newsletters8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS.This issue affects Newsletters: from n/a through 4.9.5.
ModificadaCrítica (9.8)10%💥 ExploitIcegram Email Subscribers & Newsletters5/6/202417/6/2026
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
ModificadaMedia (6.1)0.29%—Thenewsletterplugin Newsletter5/6/202417/6/2026
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…
ModificadaMedia (6.1)0.29%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe4/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue allows Reflected XSS.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.77.
AplazadaMedia (5.3)0.49%—Stefano Lissa AND THE Newsletter Team NewsletterAI17/5/202417/6/2026
Authentication Bypass by Spoofing vulnerability in Stefano Lissa & The Newsletter Team Newsletter allows Functionality Bypass.This issue affects Newsletter: from n/a through 8.2.0.
AnalizadaMedia (4.8)0.37%—Mndpsingh287 Newsletter Popup16/5/202417/6/2026
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (8.8)0.35%—Mndpsingh287 Newsletter Popup16/5/202417/6/2026
The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack
AnalizadaMedia (6.9)0.25%—Mndpsingh287 Newsletter Popup16/5/202417/6/2026
The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack
AnalizadaMedia (6.1)0.39%—Mndpsingh287 Newsletter Popup16/5/202417/6/2026
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins
AplazadaMedia (4.3)0.25%—Kibokolabs Arigato Autoresponder AND NewsletterAI14/5/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter.This issue affects Arigato Autoresponder and Newsletter: from n/a through 2.7.2.3.
AplazadaMedia (6.5)0.47%—Woocoomerce Aweber Newsletter SubscriptionAI2/5/202417/6/2026
Missing Authorization vulnerability in Kestrel WooCommerce AWeber Newsletter Subscription.This issue affects WooCommerce AWeber Newsletter Subscription: from n/a through 4.0.2.
AplazadaCrítica (9.8)0.68%—Webbax SupernewsletterAI30/4/202417/6/2026
SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privileges via the Super Newsletter module in the product_search.php components.
AnalizadaMedia (4.5)0.51%—ENL Newsletter Plugin Project Enl-newsletter26/4/202417/6/2026
The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin+ to perform SQL injection attacks
AnalizadaMedia (5.7)0.28%—ENL Newsletter Plugin Project Enl-newsletter26/4/202417/6/2026
The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary Campaigns via a CSRF attack
AnalizadaMedia (5.4)0.21%—ENL Newsletter Plugin Project Enl-newsletter26/4/202417/6/2026
The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
AplazadaCrítica (9.1)0.60%—Tribulant NewslettersAI24/4/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.5.
AplazadaAlta (7.5)0.68%—NewslettersAI24/4/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a through 4.9.5.
AplazadaMedia (5.4)0.20%—Stefano Lissa AND THE Newsletter Team NewsletterAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Stefano Lissa & The Newsletter Team Newsletter.This issue affects Newsletter: from n/a through 8.0.6.
ModificadaAlta (7.5)0.53%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages10/4/202412/8/2026
Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.
AplazadaAlta (7.1)0.35%—Katz WEB Services INC Contact Form 7 NewsletterAI31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Katz Web Services, Inc. Contact Form 7 Newsletter allows Reflected XSS.This issue affects Contact Form 7 Newsletter: from n/a through 2.2.
AplazadaAlta (7.1)0.39%—Icegram Email Subscribers AND NewslettersAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11.
ModificadaMedia (5.4)0.30%—Newsletter2go12/3/202417/6/2026
The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 4.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject…
AnalizadaAlta (7.5)0.45%—Webbax Super Newsletter3/3/202417/6/2026
An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to escalate privileges and obtain sensitive information.
Orbitaley — Vulnerabilidades