Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

301 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.21%—Omnisend Email Marketing FOR WoocommerceAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Omnisend Email Marketing for WooCommerce by Omnisend omnisend-connect.This issue affects Email Marketing for WooCommerce by Omnisend: from n/a through <= 1.14.3.
ModificadaAlta (7.5)0.53%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages10/4/202412/8/2026
Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.
ModificadaMedia (4.8)0.36%—Wpmarketingrobot Woocommerce Google Feed Manager19/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Marketing Robot WooCommerce Google Feed Manager allows Stored XSS.This issue affects WooCommerce Google Feed Manager: from n/a through 2.2.0.
ModificadaMedia (4.3)0.20%—Marketingoptimizer Marketing Optimizer29/2/202417/6/2026
The Marketing Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20200925. This is due to missing or incorrect nonce validation via the admin/main-settings-page.php file. This makes it possible for unauthenticated attackers to update the plugin's settings…
ModificadaMedia (5.4)0.24%—SAP Marketing9/1/202417/6/2026
SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very convincing phishing attack with low impact on confidentiality and integrity of the application.
ModificadaAlta (8.8)0.27%—Marketingrapel Mkrapel Regiones Y Ciudades DE Chile Para WC18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Marketing Rapel MkRapel Regiones y Ciudades de Chile para WC.This issue affects MkRapel Regiones y Ciudades de Chile para WC: from n/a through 4.3.0.
ModificadaAlta (7.5)0.55%—Omnisend Email Marketing FOR Woocommerce23/11/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Omnisend Email Marketing for WooCommerce by Omnisend.This issue affects Email Marketing for WooCommerce by Omnisend: from n/a through 1.13.8.
ModificadaMedia (4.8)0.32%—Internetmarketingninjas Internal Link Building27/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Internet Marketing Ninjas Internal Link Building plugin <= 1.2.3 versions.
ModificadaAlta (8.8)0.27%—Internetmarketingninjas Internal Link Building25/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Internet Marketing Ninjas Internal Link Building plugin <= 1.2.3 versions.
ModificadaCrítica (9.8)0.80%—Besttem Network Marketing Project Besttem Network Marketing15/9/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Besttem Network Marketing Software allows SQL Injection. This issue affects Network Marketing Software: before 1.0.2309.6.
ModificadaMedia (6.1)0.49%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe5/6/202317/6/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against…
ModificadaMedia (6.1)0.46%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages5/6/202317/6/2026
The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaCrítica (9.8)0.83%—Train Station Ticketing System Project Train Station Ticketing System31/5/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is an unknown functionality of the file manage_prices.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be launched…
ModificadaCrítica (9.8)0.73%—Theme Park Ticketing System Project Theme Park Ticketing System24/5/202317/6/2026
A vulnerability was found in SourceCodester Theme Park Ticketing System 1.0. It has been classified as critical. This affects an unknown part of the file print_ticket.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely.…
ModificadaMedia (6.1)0.38%—Mauimarketing Update Image TAG ALT Attribute10/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maui Marketing Update Image Tag Alt Attribute plugin <= 2.4.5 versions.
ModificadaMedia (6.1)0.41%—Rarathemes Vryasage Marketing Performance23/4/202317/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in VryaSage Marketing Performance plugin <= 2.0.0 versions.
ModificadaCrítica (9.8)0.83%—Phpgurukul Park Ticketing Management System27/3/202317/6/2026
Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter.
ModificadaMedia (4.8)0.46%—Phpgurukul Park Ticketing Management System27/3/202317/6/2026
Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter.
ModificadaMedia (4.8)0.39%—3commarketing 3com-asesor-de-cookies19/1/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in 3com – Asesor de Cookies para normativa española plugin <= 3.4.3 versions.
ModificadaAlta (7.5)0.52%—Oracle Marketing18/1/202317/6/2026
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of…
ModificadaMedia (5.4)0.53%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages16/1/202317/6/2026
The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as…
ModificadaAlta (7.5)0.99%—Theme Park Ticketing System Project Theme Park Ticketing System6/1/202317/6/2026
SQL injection vulnerability in sourcecodester Theme Park Ticketing System 1.0 allows remote attackers to view sensitive information via the id parameter to the /tpts/manage_user.php page.
ModificadaMedia (4.8)0.40%—Getyourguide Ticketing Project Getyourguide Ticketing12/12/202217/6/2026
The GetYourGuide Ticketing WordPress plugin before 1.0.4 does not sanitise and escape some parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (8.8)0.97%—Theme Park Ticketing System Project Theme Park Ticketing System15/6/202217/6/2026
Theme Park Ticketing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edit_ticket.php.
ModificadaCrítica (9.8)1.6%—Marketingheroes Sitesupercharger2/5/202217/6/2026
The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections
Orbitaley — Vulnerabilidades