Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 11% | — | Mail-masta Project Mail-masta | 16/9/2019 | 17/6/2026 | The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php. | |
| Modificada | Alta (7.2) | 1.7% | — | Mail-masta Project Mail-masta | 9/3/2017 | 17/6/2026 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: subscriber_email. | |
| Modificada | Alta (7.2) | 1.7% | — | Mail-masta Project Mail-masta | 9/3/2017 | 17/6/2026 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: list_id. | |
| Modificada | Alta (7.2) | 1.7% | — | Mail-masta Project Mail-masta | 9/3/2017 | 17/6/2026 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/campaign-delete.php with the GET Parameter: id. | |
| Modificada | Alta (7.2) | 1.7% | — | Mail-masta Project Mail-masta | 9/3/2017 | 17/6/2026 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: member_id. | |
| Modificada | Alta (7.2) | 1.7% | — | Mail-masta Project Mail-masta | 9/3/2017 | 17/6/2026 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: filter_list. | |
| Modificada | Alta (7.2) | 1.7% | — | Mail-masta Project Mail-masta | 9/3/2017 | 17/6/2026 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit-list.php with the GET Parameter: id. | |
| Modificada | Alta (7.2) | 1.7% | — | Mail-masta Project Mail-masta | 9/3/2017 | 17/6/2026 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/add_member.php with the GET Parameter: filter_list. | |
| Modificada | Alta (7.2) | 1.7% | — | Mail-masta Project Mail-masta | 9/3/2017 | 17/6/2026 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign.php with the GET Parameter: id. | |
| Modificada | Alta (7.2) | 1.7% | — | Mail-masta Project Mail-masta | 9/3/2017 | 17/6/2026 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign-list.php with the GET Parameter: id. | |
| Modificada | Alta (7.2) | 5.2% | — | Mail-masta Project Mail-masta | 21/2/2017 | 17/6/2026 | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authentication to Wordpress admin) with the POST Parameter: list_id. | |
| Modificada | Alta (7.2) | 5.2% | — | Mail-masta Project Mail-masta | 21/2/2017 | 17/6/2026 | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requires authentication to Wordpress admin) with the POST Parameter: camp_id. | |
| Modificada | Alta (7.2) | 5.2% | — | Mail-masta Project Mail-masta | 21/2/2017 | 17/6/2026 | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires authentication to Wordpress admin) with the GET Parameter: filter_list. | |
| Modificada | Crítica (9.8) | 5.6% | — | Mail-masta Project Mail-masta | 21/2/2017 | 17/6/2026 | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticated) with the GET Parameter: list_id. |