Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.26% | — | Thenewsletterplugin Newsletter | 9/6/2025 | 17/6/2026 | The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is… | |
| Aplazada | Media (4.7) | 0.33% | — | Automattic Newspack NewslettersAI | 6/6/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Automattic Newspack Newsletters newspack-newsletters allows Phishing.This issue affects Newspack Newsletters: from n/a through <= 3.13.0. | |
| Analizada | Media (5.3) | 0.48% | — | Anirbandutta9 News-buzzCode-projects Content Management System | 5/6/2025 | 17/6/2026 | A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/users.php. The manipulation of the argument delete leads to sql injection. The attack may be launched remotely.… | |
| Analizada | Media (5.3) | 0.48% | — | Anirbandutta9 News-buzzCode-projects Content Management System | 5/6/2025 | 17/6/2026 | A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/users.php. The manipulation of the argument change_to_admin leads to sql injection. The attack can be… | |
| Analizada | Media (6.9) | 0.58% | — | Anirbandutta9 News-buzzCode-projects Content Management System | 5/6/2025 | 17/6/2026 | A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been classified as critical. Affected is an unknown function of the file /publicposts.php. The manipulation of the argument post leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (4.8) | 0.25% | — | Thenewsletterplugin Newsletter | 3/6/2025 | 17/6/2026 | The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Alta (7.2) | 0.77% | — | Tribulant Newsletters | 31/5/2025 | 17/6/2026 | The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.9.9 via the 'file' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files on the server, allowing the execution… | |
| Analizada | Media (6.9) | 0.48% | — | Phpgurukul News Portal Project | 31/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul News Portal Project | 27/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/edit-subadmin.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul News Portal Project | 27/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument Category leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul News Portal Project | 27/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-category.php. The manipulation of the argument Category leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul News Portal Project | 27/5/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-category.php. The manipulation of the argument Category leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.3) | 0.26% | — | Jegtheme JnewsAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in jegtheme JNews jnews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JNews: from n/a through <= 11.6.16. | |
| Analizada | Media (6.9) | 0.58% | — | Phpgurukul News Portal | 18/5/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.58% | — | Phpgurukul News Portal | 18/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/contactus.php. The manipulation of the argument pagetitle leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.58% | — | Phpgurukul News Portal | 18/5/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.55% | — | Mayurik Best Online News Portal | 15/5/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Best Online News Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /search.php. The manipulation of the argument searchtitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (6.5) | 0.41% | — | NewslettersAI | 13/5/2025 | 17/6/2026 | The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versions up to, and including, 4.9.9.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.26% | — | Sendpulse Email Marketing Newsletter | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPulse Email Marketing Newsletter sendpulse-email-marketing-newsletter allows Stored XSS.This issue affects SendPulse Email Marketing Newsletter: from n/a through <= 2.1.6. | |
| Analizada | Media (4.8) | 0.31% | — | Thenewsletterplugin Newsletter | 5/5/2025 | 17/6/2026 | The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.4) | 0.24% | — | Verticalresponse Newsletter WidgetAI | 3/5/2025 | 17/6/2026 | The VerticalResponse Newsletter Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'verticalresponse' shortcode in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Alta (8.8) | 0.39% | — | Spicethemes Newsblogger | 1/5/2025 | 17/6/2026 | The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.5.4. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files… | |
| Analizada | Alta (8.8) | 1.1% | 💥 PoC | Spicethemes Newsblogger | 1/5/2025 | 17/6/2026 | The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the newsblogger_install_and_activate_plugin() function in all versions up to, and including, 0.2.5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload… | |
| Analizada | Media (5.3) | 0.53% | 💥 PoC | Code-projects News Publishing Site Dashboard | 27/4/2025 | 17/6/2026 | A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-category.php of the component Edit Category Page. The manipulation of the argument category_image leads to unrestricted upload. The attack may be… | |
| Analizada | Media (5.3) | 0.53% | — | Code-projects News Publishing Site Dashboard | 27/4/2025 | 17/6/2026 | A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /api.php. The manipulation of the argument cat_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… |