Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2706▼ 533 respecto a la semana anterior
Críticas / altas1274▼ 219 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 249 respecto a la semana anterior
250 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.0% | — | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to… | |
| Modificada | Media (5.3) | 0.95% | — | Mailpoet Newsletters | 6/11/2019 | 17/6/2026 | An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks. | |
| Modificada | Alta (8.8) | 2.2% | — | Freshmail-newsletter | 22/10/2019 | 17/6/2026 | The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring. | |
| Modificada | Crítica (9.8) | 2.1% | — | Tribulant Newsletters | 22/8/2019 | 17/6/2026 | The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. | |
| Modificada | Crítica (9.8) | 2.1% | — | Email-newsletter Project Email-newsletter | 22/8/2019 | 17/6/2026 | The email-newsletter plugin through 20.15 for WordPress has SQL injection. | |
| Modificada | Alta (8.8) | 0.67% | — | Eelv Newsletter Project Eelv Newsletter | 20/8/2019 | 17/6/2026 | The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book. | |
| Modificada | Media (6.1) | 0.91% | — | Eelv Newsletter Project Eelv Newsletter | 20/8/2019 | 17/6/2026 | The eelv-newsletter plugin before 4.6.1 for WordPress has XSS in the address book. | |
| Modificada | Alta (8.8) | 3.7% | — | Tribulant Newsletters | 15/8/2019 | 17/6/2026 | wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value. | |
| Modificada | Alta (8.8) | 0.65% | — | Newsletter BY Supsystic | 14/8/2019 | 17/6/2026 | The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF. | |
| Modificada | Media (5.4) | 1.0% | — | Tribulant Newsletters | 9/8/2019 | 17/6/2026 | The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter. | |
| Modificada | Media (6.1) | 1.3% | — | Icegram Email Subscribers & Newsletters | 28/7/2019 | 17/6/2026 | An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin/admin-ajax.php POST parameter. | |
| Modificada | Crítica (9.8) | 3.7% | — | Icegram Email Subscribers & Newsletters | 19/7/2019 | 17/6/2026 | A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. | |
| Modificada | Media (4.8) | 2.6% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in unsubscribe.html.php:3: via GET reuqest to the email variable. | |
| Modificada | Media (4.8) | 2.6% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in list-user.html.php:4: via GET request offset variable. | |
| Modificada | Media (4.8) | 2.6% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:15: via POST request variable html_id. | |
| Modificada | Media (4.8) | 2.6% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST request variable classes | |
| Modificada | Media (4.8) | 3.1% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter. | |
| Modificada | Media (4.8) | 2.9% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | |
| Modificada | Media (4.8) | 2.9% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | |
| Modificada | Media (4.8) | 2.9% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | |
| Modificada | Media (4.8) | 2.9% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | |
| Modificada | Alta (7.2) | 4.4% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request. | |
| Modificada | Crítica (9.8) | 4.2% | — | Kibokolabs Arigato Autoresponder AND Newsletter | 18/10/2018 | 17/6/2026 | The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php. | |
| Modificada | Media (6.1) | 1.2% | — | Email Subscribers & Newsletters Project Email Subscribers & Newsletters | 26/6/2018 | 17/6/2026 | Cross-site scripting vulnerability in Email Subscribers & Newsletters versions prior to 3.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.6% | 💥 Exploit | Chillcreations Ccnewsletter | 17/2/2018 | 17/6/2026 | SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011-5099. |