Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
250 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.96% | — | Tribulant Newsletters | 16/1/2024 | 17/6/2026 | The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server. | |
| Modificada | Alta (7.2) | 0.96% | — | Alphabpo Easy Newsletter Signups | 4/12/2023 | 17/6/2026 | The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin | |
| Modificada | Alta (8.8) | 0.26% | — | Kibokolabs Arigato Autoresponder AND Newsletter | 16/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.2.2 versions. | |
| Modificada | Crítica (9.8) | 0.70% | — | Activedesign Newsletterpop | 15/11/2023 | 17/6/2026 | In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions. The method `NewsletterpopsendVerificationModuleFrontController::checkEmailSubscription()` has sensitive SQL calls that can be… | |
| Modificada | Alta (8.8) | 0.30% | — | Tribulant Newsletters | 10/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions. | |
| Modificada | Media (5.4) | 0.40% | — | Happybox Newsletter & Bulk Email Sender | 25/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in HappyBox Newsletter & Bulk Email Sender – Email Newsletter Plugin for WordPress plugin <= 2.0.1 versions. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Fieldthemes Fieldpopupnewsletter | 8/9/2023 | 17/6/2026 | FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php. | |
| Modificada | Media (5.4) | 0.51% | — | Thenewsletterplugin Newsletter | 7/9/2023 | 17/6/2026 | The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Modificada | Media (6.1) | 0.36% | — | Simplephpscripts Newsletter Script PHP | 7/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SimplePHPscripts NewsLetter Script PHP 2.4. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of… | |
| Modificada | Crítica (9.8) | 1.6% | — | Xyzscripts Newsletter Manager | 7/6/2023 | 17/6/2026 | The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization function. This potentially makes it possible for unauthenticated attackers to… | |
| Modificada | Media (6.1) | 0.49% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 5/6/2023 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against… | |
| Modificada | Media (6.1) | 0.46% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 5/6/2023 | 17/6/2026 | The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.1) | 0.55% | — | Eelv Newsletter Project Eelv Newsletter | 4/6/2023 | 16/6/2026 | A vulnerability was found in EELV Newsletter Plugin 2.x on WordPress. It has been rated as problematic. Affected by this issue is the function style_newsletter of the file lettreinfo.php. The manipulation of the argument email leads to cross site scripting. The attack may be launched remotely. The name of the patch is… | |
| Modificada | Alta (8.8) | 0.39% | — | Newsletter Popup Project Newsletter Popup | 30/5/2023 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks as the wp_newsletter_show_localrecord page is not protected with a nonce. | |
| Modificada | Media (6.1) | 0.51% | — | Newsletter Popup Project Newsletter Popup | 30/5/2023 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Thenewsletterplugin Newsletter | 23/5/2023 | 17/6/2026 | Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Idnovate Popup Module (ON Entering, Exit Popup, ADD Product) AND Newsletter | 12/4/2023 | 17/6/2026 | Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups(). | |
| Modificada | Media (4.8) | 0.39% | — | Kibokolabs Arigato Autoresponder AND Newsletter | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Kibokolabs Arigato Autoresponder AND Newsletter | 7/4/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1.1 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Kibokolabs Arigato Autoresponder AND Newsletter | 7/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1.1 versions. | |
| Modificada | Media (4.8) | 0.46% | — | Kibokolabs Arigato Autoresponder AND Newsletter | 27/2/2023 | 17/6/2026 | The Arigato Autoresponder and Newsletter WordPress plugin before 2.1.7.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.4) | 0.53% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 16/1/2023 | 17/6/2026 | The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as… | |
| Modificada | Alta (7.5) | 0.69% | — | FP Newsletter Project FP Newsletter | 14/12/2022 | 17/6/2026 | An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via unsubscribeAction operations. | |
| Modificada | Alta (7.5) | 0.69% | — | FP Newsletter Project FP Newsletter | 14/12/2022 | 17/6/2026 | An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via createAction operations. | |
| Modificada | Alta (7.5) | 0.62% | — | FP Newsletter Project FP Newsletter | 14/12/2022 | 17/6/2026 | An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Attackers can unsubscribe everyone via a series of modified subscription UIDs in deleteAction operations. |