Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

250 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.96%—Tribulant Newsletters16/1/202417/6/2026
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.
ModificadaAlta (7.2)0.96%—Alphabpo Easy Newsletter Signups4/12/202317/6/2026
The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
ModificadaAlta (8.8)0.26%—Kibokolabs Arigato Autoresponder AND Newsletter16/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.2.2 versions.
ModificadaCrítica (9.8)0.70%—Activedesign Newsletterpop15/11/202317/6/2026
In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions. The method `NewsletterpopsendVerificationModuleFrontController::checkEmailSubscription()` has sensitive SQL calls that can be…
ModificadaAlta (8.8)0.30%—Tribulant Newsletters10/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions.
ModificadaMedia (5.4)0.40%—Happybox Newsletter & Bulk Email Sender25/10/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in HappyBox Newsletter & Bulk Email Sender – Email Newsletter Plugin for WordPress plugin <= 2.0.1 versions.
ModificadaMedia (6.1)1.4%💥 ExploitFieldthemes Fieldpopupnewsletter8/9/202317/6/2026
FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php.
ModificadaMedia (5.4)0.51%—Thenewsletterplugin Newsletter7/9/202317/6/2026
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level…
ModificadaMedia (6.1)0.36%—Simplephpscripts Newsletter Script PHP7/7/202317/6/2026
A vulnerability, which was classified as problematic, was found in SimplePHPscripts NewsLetter Script PHP 2.4. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of…
ModificadaCrítica (9.8)1.6%—Xyzscripts Newsletter Manager7/6/202317/6/2026
The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization function. This potentially makes it possible for unauthenticated attackers to…
ModificadaMedia (6.1)0.49%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe5/6/202317/6/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against…
ModificadaMedia (6.1)0.46%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages5/6/202317/6/2026
The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.55%—Eelv Newsletter Project Eelv Newsletter4/6/202316/6/2026
A vulnerability was found in EELV Newsletter Plugin 2.x on WordPress. It has been rated as problematic. Affected by this issue is the function style_newsletter of the file lettreinfo.php. The manipulation of the argument email leads to cross site scripting. The attack may be launched remotely. The name of the patch is…
ModificadaAlta (8.8)0.39%—Newsletter Popup Project Newsletter Popup30/5/202317/6/2026
The Newsletter Popup WordPress plugin through 1.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks as the wp_newsletter_show_localrecord page is not protected with a nonce.
ModificadaMedia (6.1)0.51%—Newsletter Popup Project Newsletter Popup30/5/202317/6/2026
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.1)1.2%💥 ExploitThenewsletterplugin Newsletter23/5/202317/6/2026
Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.
ModificadaCrítica (9.8)3.0%💥 ExploitIdnovate Popup Module (ON Entering, Exit Popup, ADD Product) AND Newsletter12/4/202317/6/2026
Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups().
ModificadaMedia (4.8)0.39%—Kibokolabs Arigato Autoresponder AND Newsletter7/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1 versions.
ModificadaMedia (6.1)0.41%—Kibokolabs Arigato Autoresponder AND Newsletter7/4/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1.1 versions.
ModificadaMedia (5.4)0.38%—Kibokolabs Arigato Autoresponder AND Newsletter7/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1.1 versions.
ModificadaMedia (4.8)0.46%—Kibokolabs Arigato Autoresponder AND Newsletter27/2/202317/6/2026
The Arigato Autoresponder and Newsletter WordPress plugin before 2.1.7.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (5.4)0.53%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages16/1/202317/6/2026
The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as…
ModificadaAlta (7.5)0.69%—FP Newsletter Project FP Newsletter14/12/202217/6/2026
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via unsubscribeAction operations.
ModificadaAlta (7.5)0.69%—FP Newsletter Project FP Newsletter14/12/202217/6/2026
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via createAction operations.
ModificadaAlta (7.5)0.62%—FP Newsletter Project FP Newsletter14/12/202217/6/2026
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Attackers can unsubscribe everyone via a series of modified subscription UIDs in deleteAction operations.
Orbitaley — Vulnerabilidades