Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
250 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 0.67% | — | FP Newsletter Project FP Newsletter | 14/12/2022 | 17/6/2026 | An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. There is a CAPTCHA bypass that can lead to subscribing many people. | |
| Modificada | Alta (8.8) | 0.76% | — | Icegram Email Subscribers & Newsletters | 12/12/2022 | 17/6/2026 | The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber | |
| Modificada | Crítica (9.8) | 1.2% | — | Newsletter Subscribe (popup + Regular Module) Project Newsletter Subscribe (popup + Regular Module) | 12/10/2022 | 17/6/2026 | OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at index.php?route=extension/module/so_newletter_custom_popup/newsletter. | |
| Modificada | Crítica (9.8) | 1.5% | — | Newsletter Module Project Newsletter Module | 5/7/2022 | 17/6/2026 | Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php. | |
| Modificada | Media (4.8) | 0.59% | — | Thenewsletterplugin Newsletter | 20/6/2022 | 17/6/2026 | The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Thenewsletterplugin Newsletter | 13/6/2022 | 17/6/2026 | The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9… | |
| Modificada | Alta (8.8) | 4.2% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 7/3/2022 | 17/6/2026 | The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place… | |
| Modificada | Media (4.3) | 0.47% | — | Ec-cube E-mail Newsletter Management | 24/2/2022 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in EC-CUBE plugin 'Mail Magazine Management Plugin' ver4.0.0 to 4.1.1 (for EC-CUBE 4 series) and ver1.0.0 to 1.0.4 (for EC-CUBE 3 series) allows a remote unauthenticated attacker to hijack the authentication of an administrator via a specially crafted page, and Mail… | |
| Modificada | Media (6.1) | 0.80% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 14/2/2022 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Media (6.1) | 0.81% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 24/1/2022 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 0.90% | — | Keszites Simple Popup Newsletter | 16/8/2021 | 17/6/2026 | The Simple Popup Newsletter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/simple-popup-newsletter.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.7. | |
| Modificada | Crítica (9.8) | 1.00% | — | Newsletter Project Newsletter | 13/8/2021 | 17/6/2026 | The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection. | |
| Modificada | Alta (8.8) | 0.70% | — | Sola-newsletters Project Sola-newsletters | 5/8/2021 | 17/6/2026 | The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.23. | |
| Modificada | Media (6.1) | 0.75% | — | Ec-cube Email Newsletters Management | 22/6/2021 | 17/6/2026 | Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform a specific operation. | |
| Modificada | Media (6.5) | 0.86% | — | Thenewsletterplugin Newsletter | 1/1/2021 | 17/6/2026 | A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the… | |
| Modificada | Alta (8.8) | 2.1% | — | Tribulant Newsletter | 1/1/2021 | 17/6/2026 | Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that… | |
| Modificada | Media (5.3) | 1.6% | — | Icegram Email Subscribers & Newsletters | 10/9/2020 | 17/6/2026 | Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing. | |
| Modificada | Media (4.9) | 2.0% | — | Icegram Email Subscribers & Newsletters | 17/7/2020 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields. | |
| Modificada | Media (6.5) | 0.92% | — | Icegram Email Subscribers & Newsletters | 17/7/2020 | 17/6/2026 | Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link. | |
| Modificada | Crítica (9.8) | 1.4% | — | Magento Advanced Newsletter | 9/3/2020 | 17/6/2026 | SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category_id/ PATH_INFO. | |
| Modificada | Crítica (9.8) | 85% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 8/1/2020 | 17/6/2026 | There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability). | |
| Modificada | Media (5.3) | 71% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure. | |
| Modificada | Media (6.3) | 0.97% | — | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns. | |
| Modificada | Media (5.3) | 1.2% | — | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request. | |
| Modificada | Media (5.4) | 0.56% | — | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings. |