Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
3270 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.34% | — | Print PDF Email BY PrintfriendlyAI | 11/7/2026 | 13/7/2026 | The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and including, 5.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.8) | 0.38% | — | Axllent MailpitAI | 10/7/2026 | 13/7/2026 | Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is incomplete because the tools.IsInternalIP deny-list in internal/tools/net.go relies on Go's standard library classification helpers and does not block IPv6 transition mechanisms or prefixes such as… | |
| Aplazada | Media (4.9) | 0.51% | — | Mail MintAI | 10/7/2026 | 14/7/2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to generic SQL Injection via the 'recipients' parameter in all versions up to, and including, 1.24.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Aplazada | Media (5.1) | 0.16% | — | Samsung EmailAI | 10/7/2026 | 10/7/2026 | Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files within the application sandbox. | |
| Aplazada | Media (6.1) | 0.36% | — | Brevo Newsletter Smtp Email Marketing Subscribe FormsAI | 10/7/2026 | 10/7/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Crítica (9.2) | 1.4% | 💥 Exploit | Acymailing | 9/7/2026 | 23/7/2026 | Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database access and data leakage. | |
| Aplazada | Alta (7.2) | 0.59% | — | Connect Contact Form 7 AND MailchimpAI | 9/7/2026 | 9/7/2026 | The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp Merge Field Values in all versions up to, and including, 0.9.78.06 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (4.9) | 0.44% | — | Mailmint Mail MintAI | 9/7/2026 | 9/7/2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to time-based SQL Injection via the 'contact_ids' parameter in all versions up to, and including, 1.24.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation… | |
| Aplazada | Media (6.4) | 0.35% | — | AcymailingAI | 9/7/2026 | 9/7/2026 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' attribute in all versions up to, and including, 10.10.2 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Pendiente de análisis | Alta (8.8) | 0.18% | — | OpenjdkAIUbuntuAIMailcapAIFreedesktop Xdg-desktop-portal-gtkAI | 8/7/2026 | 14/7/2026 | A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk… | |
| Aplazada | Media (4.3) | 0.47% | — | Blog Dash Email SubscribersAI | 2/7/2026 | 2/7/2026 | The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This… | |
| Aplazada | Media (4.3) | 0.14% | — | Gmail SmtpAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | Omnisend Email Marketing FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions. | |
| Aplazada | Alta (8.3) | 0.30% | — | Mailchimp BlockAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Siteground Email MarketingAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wedevs WemailAI | 26/6/2026 | 18/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs weMail wemail allows Reflected XSS.This issue affects weMail: from n/a through 2.1.2. | |
| Aplazada | Alta (8.8) | 0.51% | — | Email Address Encoder Email Encoder PremiumAITillkruss Email Address EncoderAI | 25/6/2026 | 25/6/2026 | The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks | |
| Aplazada | Alta (8.8) | 0.71% | — | MailerupAI | 24/6/2026 | 25/6/2026 | Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /api/auth/register/, in MailerUp <1.0.1 allows a remote, unauthenticated attacker to self-register a working account on instances where registration is intended to be restricted, because the endpoint… | |
| Aplazada | Media (5.3) | 0.51% | — | MailerupAI | 24/6/2026 | 25/6/2026 | Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mailerup <1.0.0 on all platforms allows remote unauthenticated attackers to redirect victims to arbitrary external sites and conduct phishing attacks via a crafted u query parameter, because the URL… | |
| Aplazada | Alta (7.2) | 0.36% | — | Email Javascript CloakAI | 24/6/2026 | 25/6/2026 | The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to, and including, 1.03 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.44% | — | SeppmailAI | 18/6/2026 | 22/6/2026 | SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to create new files outside the intended directory, potentially placing files in web-accessible locations. | |
| Aplazada | Alta (7.1) | 0.28% | — | Wedevs WemailAI | 17/6/2026 | 17/6/2026 | The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Integration FOR Mailchimp AND Contact Form 7AI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions. | |
| Aplazada | Alta (7.5) | 0.48% | — | Omnisend Email Marketing FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Speakout Email PetitionsAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions. |