Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.15% | — | Google NewsAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Olav Kolbu Google News allows Stored XSS. This issue affects Google News: from n/a through 2.5.1. | |
| Aplazada | Alta (7.1) | 0.23% | — | Kibokolabs Arigato Autoresponder AND NewsletterAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Arigato Autoresponder and Newsletter bft-autoresponder allows Reflected XSS.This issue affects Arigato Autoresponder and Newsletter: from n/a through <= 2.7.2.4. | |
| Aplazada | Alta (7.1) | 0.15% | — | Beke RO BknewstickerAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in beke_ro Bknewsticker bknewsticker allows Stored XSS.This issue affects Bknewsticker: from n/a through <= 1.0.5. | |
| Aplazada | Alta (7.1) | 0.29% | — | Kush Sharma Kush Micro NewsAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kush Sharma Kush Micro News kush-micro-news allows Stored XSS.This issue affects Kush Micro News: from n/a through <= 1.6.7. | |
| Aplazada | Alta (7.1) | 0.21% | — | Newsboard Post AND RSS ScrollerAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in NewsBoard Plugin NewsBoard Post and RSS Scroller newsboard allows Stored XSS.This issue affects NewsBoard Post and RSS Scroller: from n/a through <= 1.2.12. | |
| Aplazada | Media (6.5) | 0.40% | — | Blazethemes News KIT Elementor AddonsAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Stored XSS.This issue affects News Kit Elementor Addons: from n/a through <= 1.4.2. | |
| Aplazada | Media (6.5) | 0.40% | — | News Element Elementor Blog MagazineAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webangon News Element Elementor Blog Magazine news-element allows DOM-Based XSS.This issue affects News Element Elementor Blog Magazine: from n/a through <= 1.0.9. | |
| Aplazada | Alta (8.1) | 0.84% | — | Informweb News AND Blog Designer PackAIPHPAI | 1/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InfornWeb News & Blog Designer Pack blog-designer-pack allows PHP Local File Inclusion.This issue affects News & Blog Designer Pack: from n/a through <= 4.0. | |
| Aplazada | Media (6.5) | 0.26% | — | Breaking News WPAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in doit Breaking News WP breaking-news-wp allows Cross Site Request Forgery.This issue affects Breaking News WP: from n/a through <= 1.3. | |
| Aplazada | Media (5.9) | 0.37% | — | Doit Breaking News WPAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in doit Breaking News WP breaking-news-wp allows Stored XSS.This issue affects Breaking News WP: from n/a through <= 1.3. | |
| Aplazada | Media (6.5) | 0.36% | — | Athemeart News Magazine AND Blog ElementsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aThemeArt News, Magazine and Blog Elements news-magazine-and-blog-elements allows Stored XSS.This issue affects News, Magazine and Blog Elements: from n/a through <= 1.3. | |
| Aplazada | Alta (7.6) | 0.52% | 💥 PoC | Tribulant Software NewslettersAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Software Newsletters newsletters-lite allows SQL Injection.This issue affects Newsletters: from n/a through <= 4.9.9.7. | |
| Aplazada | Media (6.5) | 0.36% | — | 99colorthemes RainbownewsAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 99colorthemes RainbowNews allows Stored XSS.This issue affects RainbowNews: from n/a through 1.0.7. | |
| Aplazada | Media (6.5) | 0.36% | — | NewseqoAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefunction newseqo allows Stored XSS.This issue affects newseqo: from n/a through 2.1.1. | |
| Aplazada | Alta (7.2) | 0.35% | — | NewslettersAI | 26/3/2025 | 17/6/2026 | The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the logging functionality in all versions up to, and including, 4.9.9.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (6.1) | 0.25% | — | Tribulant Newsletters | 22/3/2025 | 17/6/2026 | The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versions up to, and including, 4.9.9.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Crítica (9.8) | 0.43% | — | CM Informatics CM NewsAI | 20/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection. This issue affects CM News: through 6.0. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Modificada | Media (6.1) | 0.15% | — | Ppdpurveyor Google News Editors Picks Feed Generator | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PPDPurveyor Google News Editors Picks Feed Generator google-news-editors-picks-news-feeds allows Stored XSS.This issue affects Google News Editors Picks Feed Generator: from n/a through <= 2.1. | |
| Aplazada | Media (5.3) | 0.28% | 💥 PoC | JnewsAI | 5/3/2025 | 17/6/2026 | The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 11.6.6. This is due to the plugin not properly validate if the user can register option is enabled prior to creating a user though the register_handler()… | |
| Analizada | Crítica (9.8) | 2.2% | 💥 PoC | Spicethemes Newscrunch | 4/3/2025 | 17/6/2026 | The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload… | |
| Analizada | Alta (8.8) | 0.53% | 💥 PoC | Spicethemes Newscrunch | 4/3/2025 | 17/6/2026 | The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation on the newscrunch_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files via a… | |
| Aplazada | Alta (7.1) | 0.39% | — | Pillardev Easy Automatic Newsletter LiteAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PillarDev Easy Automatic Newsletter Lite easy-automatic-newsletter allows Reflected XSS.This issue affects Easy Automatic Newsletter Lite: from n/a through <= 3.2.0. | |
| Aplazada | Alta (7.1) | 0.30% | — | Keir Whitaker Twitter News FeedAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keir Whitaker Twitter News Feed twitter-news-feed allows Reflected XSS.This issue affects Twitter News Feed: from n/a through <= 1.1.1. | |
| Analizada | Crítica (9.3) | 0.42% | — | Mayurik Best Online News Portal | 3/3/2025 | 17/6/2026 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in search.php. | |
| Analizada | Crítica (9.3) | 0.42% | — | Mayurik Best Online News Portal | 3/3/2025 | 17/6/2026 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php. |