Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
301 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.21% | — | Omnisend Email Marketing FOR WoocommerceAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Omnisend Email Marketing for WooCommerce by Omnisend omnisend-connect.This issue affects Email Marketing for WooCommerce by Omnisend: from n/a through <= 1.14.3. | |
| Modificada | Alta (7.5) | 0.53% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 10/4/2024 | 12/8/2026 | Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5. | |
| Modificada | Media (4.8) | 0.36% | — | Wpmarketingrobot Woocommerce Google Feed Manager | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Marketing Robot WooCommerce Google Feed Manager allows Stored XSS.This issue affects WooCommerce Google Feed Manager: from n/a through 2.2.0. | |
| Modificada | Media (4.3) | 0.20% | — | Marketingoptimizer Marketing Optimizer | 29/2/2024 | 17/6/2026 | The Marketing Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20200925. This is due to missing or incorrect nonce validation via the admin/main-settings-page.php file. This makes it possible for unauthenticated attackers to update the plugin's settings… | |
| Modificada | Media (5.4) | 0.24% | — | SAP Marketing | 9/1/2024 | 17/6/2026 | SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very convincing phishing attack with low impact on confidentiality and integrity of the application. | |
| Modificada | Alta (8.8) | 0.27% | — | Marketingrapel Mkrapel Regiones Y Ciudades DE Chile Para WC | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marketing Rapel MkRapel Regiones y Ciudades de Chile para WC.This issue affects MkRapel Regiones y Ciudades de Chile para WC: from n/a through 4.3.0. | |
| Modificada | Alta (7.5) | 0.55% | — | Omnisend Email Marketing FOR Woocommerce | 23/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Omnisend Email Marketing for WooCommerce by Omnisend.This issue affects Email Marketing for WooCommerce by Omnisend: from n/a through 1.13.8. | |
| Modificada | Media (4.8) | 0.32% | — | Internetmarketingninjas Internal Link Building | 27/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Internet Marketing Ninjas Internal Link Building plugin <= 1.2.3 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | Internetmarketingninjas Internal Link Building | 25/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Internet Marketing Ninjas Internal Link Building plugin <= 1.2.3 versions. | |
| Modificada | Crítica (9.8) | 0.80% | — | Besttem Network Marketing Project Besttem Network Marketing | 15/9/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Besttem Network Marketing Software allows SQL Injection. This issue affects Network Marketing Software: before 1.0.2309.6. | |
| Modificada | Media (6.1) | 0.49% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 5/6/2023 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against… | |
| Modificada | Media (6.1) | 0.46% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 5/6/2023 | 17/6/2026 | The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Crítica (9.8) | 0.83% | — | Train Station Ticketing System Project Train Station Ticketing System | 31/5/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is an unknown functionality of the file manage_prices.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be launched… | |
| Modificada | Crítica (9.8) | 0.73% | — | Theme Park Ticketing System Project Theme Park Ticketing System | 24/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Theme Park Ticketing System 1.0. It has been classified as critical. This affects an unknown part of the file print_ticket.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely.… | |
| Modificada | Media (6.1) | 0.38% | — | Mauimarketing Update Image TAG ALT Attribute | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maui Marketing Update Image Tag Alt Attribute plugin <= 2.4.5 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Rarathemes Vryasage Marketing Performance | 23/4/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in VryaSage Marketing Performance plugin <= 2.0.0 versions. | |
| Modificada | Crítica (9.8) | 0.83% | — | Phpgurukul Park Ticketing Management System | 27/3/2023 | 17/6/2026 | Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter. | |
| Modificada | Media (4.8) | 0.46% | — | Phpgurukul Park Ticketing Management System | 27/3/2023 | 17/6/2026 | Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter. | |
| Modificada | Media (4.8) | 0.39% | — | 3commarketing 3com-asesor-de-cookies | 19/1/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in 3com – Asesor de Cookies para normativa española plugin <= 3.4.3 versions. | |
| Modificada | Alta (7.5) | 0.52% | — | Oracle Marketing | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of… | |
| Modificada | Media (5.4) | 0.53% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 16/1/2023 | 17/6/2026 | The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as… | |
| Modificada | Alta (7.5) | 0.99% | — | Theme Park Ticketing System Project Theme Park Ticketing System | 6/1/2023 | 17/6/2026 | SQL injection vulnerability in sourcecodester Theme Park Ticketing System 1.0 allows remote attackers to view sensitive information via the id parameter to the /tpts/manage_user.php page. | |
| Modificada | Media (4.8) | 0.40% | — | Getyourguide Ticketing Project Getyourguide Ticketing | 12/12/2022 | 17/6/2026 | The GetYourGuide Ticketing WordPress plugin before 1.0.4 does not sanitise and escape some parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 0.97% | — | Theme Park Ticketing System Project Theme Park Ticketing System | 15/6/2022 | 17/6/2026 | Theme Park Ticketing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edit_ticket.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Marketingheroes Sitesupercharger | 2/5/2022 | 17/6/2026 | The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections |