Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.2) | 0.23% | — | Cutephp CutenewsAI | 21/9/2026 | 22/9/2026 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in the context of an authenticated user's session via a javascript: URI rendered as an unsanitized clickable link on the msg_info page. | |
| Aplazada | Media (5.8) | 0.21% | — | Cutephp CutenewsAI | 21/9/2026 | 25/9/2026 | Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __referer) via a crafted base64-encoded serialized PHP payload submitted as a POST parameter. | |
| Aplazada | Media (5.8) | 0.22% | — | Cutephp CutenewsAI | 21/9/2026 | 22/9/2026 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during POST messages to index.php. | |
| Aplazada | Crítica (9.1) | 0.27% | — | Cutephp CutenewsAI | 21/9/2026 | 24/9/2026 | CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality). | |
| Aplazada | Media (6.1) | 0.34% | — | Cutephp CutenewsAI | 21/9/2026 | 22/9/2026 | Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as "><script>alert(1)</script>). | |
| Aplazada | Alta (7.2) | 0.53% | — | Cutephp CutenewsAI | 21/9/2026 | 22/9/2026 | Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell. | |
| Analizada | Media (4.8) | 0.26% | — | Thenewsletterplugin Newsletter | 9/6/2025 | 17/6/2026 | The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.26% | — | Thenewsletterplugin Newsletter | 9/6/2025 | 17/6/2026 | The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is… | |
| Analizada | Media (4.8) | 0.25% | — | Thenewsletterplugin Newsletter | 3/6/2025 | 17/6/2026 | The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.31% | — | Thenewsletterplugin Newsletter | 5/5/2025 | 17/6/2026 | The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Crítica (9.8) | 0.52% | — | Cozythemes Revivenews | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in CozyThemes ReviveNews allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReviveNews: from n/a through 1.0.2. | |
| Aplazada | Media (6.4) | 0.34% | — | Simplenews Simple NewsAI | 25/10/2024 | 17/6/2026 | The Simple News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'news' shortcode in all versions up to, and including, 2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.6) | 0.24% | — | OnlinenewssiteAI | 7/10/2024 | 5/7/2026 | OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ endpoint. | |
| Modificada | Media (6.1) | 0.29% | — | Thenewsletterplugin Newsletter | 5/6/2024 | 17/6/2026 | The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Modificada | Media (5.4) | 0.51% | — | Thenewsletterplugin Newsletter | 7/9/2023 | 17/6/2026 | The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Modificada | Media (6.1) | 1.2% | — | Thenewsletterplugin Newsletter | 23/5/2023 | 17/6/2026 | Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script. | |
| Modificada | Media (6.5) | 0.31% | — | Moodle-block Sitenews Project Moodle-block Sitenews | 27/12/2022 | 17/6/2026 | A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file block_sitenews.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.1 is able to address this… | |
| Modificada | Media (4.8) | 0.59% | — | Thenewsletterplugin Newsletter | 20/6/2022 | 17/6/2026 | The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed | |
| Modificada | Media (6.1) | 1.9% | — | Thenewsletterplugin Newsletter | 13/6/2022 | 17/6/2026 | The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9… | |
| Modificada | Media (6.5) | 0.86% | — | Thenewsletterplugin Newsletter | 1/1/2021 | 17/6/2026 | A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the… | |
| Modificada | Alta (8.8) | 2.1% | — | Cutephp Cutenews | 25/3/2020 | 17/6/2026 | CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors. | |
| Modificada | Media (6.1) | 0.77% | — | Cutephp Cutenews | 25/3/2020 | 17/6/2026 | Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.3) | 2.5% | — | Md-systems Simplenews | 9/1/2020 | 16/6/2026 | The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page. | |
| Modificada | Alta (8.8) | 52% | — | Cutephp Cutenews | 22/4/2019 | 17/6/2026 | An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be… | |
| Modificada | Media (5.4) | 0.27% | — | Tribunenews365 John Macarthur | 27/9/2014 | 17/6/2026 | The John MacArthur (aka com.john.macarthur) application 1.0.26 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |