Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

250 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.2%—Icegram Email Subscribers & Newsletters26/1/201817/6/2026
An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading of a CSV data file with all subscriber data.
ModificadaMedia (6.1)1.4%—E-goi Smart Marketing SMS AND Newsletters Forms1/1/201817/6/2026
The E-goi Smart Marketing SMS and Newsletters Forms plugin before 2.0.0 for WordPress has XSS via the admin/partials/custom/egoi-for-wp-form_egoi.php url parameter.
ModificadaMedia (6.1)0.64%—Stivasoft Phpjabbers Newsletter Script30/12/201717/6/2026
PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel.
ModificadaMedia (6.8)1.1%—Mailpoet Newsletters26/8/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote attackers to hijack the authentication of arbitrary users.
ModificadaAlta (7.5)1.7%—Mailpoet Newsletters27/7/201417/6/2026
Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors.
ModificadaAlta (7.5)61%💥 ExploitMailpoet Newsletters27/7/201417/6/2026
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.
ModificadaMedia (6.5)2.3%💥 ExploitENL Newsletter Plugin Project Enl-newsletter11/7/201417/6/2026
SQL injection vulnerability in the ENL Newsletter (enl-newsletter) plugin 1.0.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in the enl-add-new page to wp-admin/admin.php.
ModificadaMedia (4.3)1.6%—Envialosimple Email Marketing Y Newsletters2/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in paginas/vista-previa-form.php in the EnvialoSimple: Email Marketing and Newsletters (envialosimple-email-marketing-y-newsletters-gratis) plugin before 1.98 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) FormID or (2)…
ModificadaMedia (6.5)4.3%💥 ExploitWysija Newsletters Project Wysija Newsletters24/3/201416/6/2026
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated…
ModificadaMedia (6.8)0.99%—Xyzscripts Newsletter Manager16/1/201416/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Newsletter Manager plugin 1.0.2 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change an email address or (2) conduct script insertion attacks. NOTE: the provenance of this…
ModificadaMedia (4.3)2.1%—Xyzscripts Newsletter Manager16/1/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Newsletter Manager plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) xyz_em_campName to admin/create_campaign.php or (2) admin/edit_campaign.php, (3) xyz_em_email parameter to admin/edit_email.php, (4)…
ModificadaMedia (4.3)1.6%—Xyzscripts Newsletter Manager16/1/201416/6/2026
Cross-site scripting (XSS) vulnerability in admin/test_mail.php in the Newsletter Manager plugin 1.0.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaAlta (7.5)1.3%💥 ExploitChillcreations MOD Ccnewsletter14/8/201216/6/2026
SQL injection vulnerability in helper/popup.php in the ccNewsletter (mod_ccnewsletter) component 1.0.7 through 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (5)11%💥 ExploitWordpress Plugin Newsletter Plugin19/6/201216/6/2026
Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the data parameter.
ModificadaAlta (7.5)1.0%💥 ExploitWanewsletter9/10/201116/6/2026
SQL injection vulnerability in index.php in WAnewsletter 2.1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.0%—Chris Wederka TGM Newsletter19/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in the TGM-Newsletter (tgm_newsletter) extension 0.0.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.1%—Chris Wederka TGM Newsletter19/3/201016/6/2026
SQL injection vulnerability in the TGM-Newsletter (tgm_newsletter) extension 0.0.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (5.8)43%💥 ExploitChillcreations COM Ccnewsletter2/2/201016/6/2026
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.
ModificadaMedia (5)2.2%💥 ExploitR2newsletter R2 Newsletter LiteR2newsletter R2 Newsletter PROR2newsletter R2 Newsletter Stats27/7/200916/6/2026
R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb.
ModificadaAlta (7.5)2.5%💥 ExploitXigla Absolute Newsletter14/7/200916/6/2026
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
ModificadaAlta (7.5)1.00%💥 ExploitActivewebsoftwares Active Newsletter25/2/200916/6/2026
Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the password parameter (aka password field), to (a) Subscriber.asp or (b) start.asp. NOTE: some of these…
ModificadaMedia (6.8)1.9%💥 ExploitQuirm Simple PHP Newsletter29/1/200916/6/2026
Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the olang parameter to (1) mail.php and (2) mailbar.php.
ModificadaMedia (6.8)2.4%💥 ExploitPHP Multiple Newsletters15/12/200816/6/2026
Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
ModificadaMedia (4.3)3.4%💥 ExploitPhpmultiplenewsletters15/12/200816/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
ModificadaAlta (7.5)2.7%💥 ExploitShiftthis Shifthis Newsletter21/10/200816/6/2026
SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter, a different vector than CVE-2008-0683.
Orbitaley — Vulnerabilidades