Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

250 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)0.67%—FP Newsletter Project FP Newsletter14/12/202217/6/2026
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. There is a CAPTCHA bypass that can lead to subscribing many people.
ModificadaAlta (8.8)0.76%—Icegram Email Subscribers & Newsletters12/12/202217/6/2026
The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber
ModificadaCrítica (9.8)1.2%—Newsletter Subscribe (popup + Regular Module) Project Newsletter Subscribe (popup + Regular Module)12/10/202217/6/2026
OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at index.php?route=extension/module/so_newletter_custom_popup/newsletter.
ModificadaCrítica (9.8)1.5%—Newsletter Module Project Newsletter Module5/7/202217/6/2026
Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.
ModificadaMedia (4.8)0.59%—Thenewsletterplugin Newsletter20/6/202217/6/2026
The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed
ModificadaMedia (6.1)1.9%💥 ExploitThenewsletterplugin Newsletter13/6/202217/6/2026
The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9…
ModificadaAlta (8.8)4.2%💥 ExploitIcegram Email Subscribers & Newsletters7/3/202217/6/2026
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place…
ModificadaMedia (4.3)0.47%—Ec-cube E-mail Newsletter Management24/2/202217/6/2026
Cross-site request forgery (CSRF) vulnerability in EC-CUBE plugin 'Mail Magazine Management Plugin' ver4.0.0 to 4.1.1 (for EC-CUBE 4 series) and ver1.0.0 to 1.0.4 (for EC-CUBE 3 series) allows a remote unauthenticated attacker to hijack the authentication of an administrator via a specially crafted page, and Mail…
ModificadaMedia (6.1)0.80%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe14/2/202217/6/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
ModificadaMedia (6.1)0.81%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe24/1/202217/6/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (6.1)0.90%—Keszites Simple Popup Newsletter16/8/202117/6/2026
The Simple Popup Newsletter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/simple-popup-newsletter.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.7.
ModificadaCrítica (9.8)1.00%—Newsletter Project Newsletter13/8/202117/6/2026
The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.
ModificadaAlta (8.8)0.70%—Sola-newsletters Project Sola-newsletters5/8/202117/6/2026
The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.23.
ModificadaMedia (6.1)0.75%—Ec-cube Email Newsletters Management22/6/202117/6/2026
Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform a specific operation.
ModificadaMedia (6.5)0.86%—Thenewsletterplugin Newsletter1/1/202117/6/2026
A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the…
ModificadaAlta (8.8)2.1%—Tribulant Newsletter1/1/202117/6/2026
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that…
ModificadaMedia (5.3)1.6%—Icegram Email Subscribers & Newsletters10/9/202017/6/2026
Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing.
ModificadaMedia (4.9)2.0%—Icegram Email Subscribers & Newsletters17/7/202017/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields.
ModificadaMedia (6.5)0.92%—Icegram Email Subscribers & Newsletters17/7/202017/6/2026
Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.
ModificadaCrítica (9.8)1.4%—Magento Advanced Newsletter9/3/202017/6/2026
SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category_id/ PATH_INFO.
ModificadaCrítica (9.8)85%💥 ExploitIcegram Email Subscribers & Newsletters8/1/202017/6/2026
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
ModificadaMedia (5.3)71%💥 ExploitIcegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
ModificadaMedia (6.3)0.97%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
ModificadaMedia (5.3)1.2%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request.
ModificadaMedia (5.4)0.56%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
Orbitaley — Vulnerabilidades