Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.3) | — | — | Sendpress NewslettersAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions. | |
| Aplazada | Alta (7.2) | 0.27% | — | NewsletterAI | 2/10/2026 | 3/10/2026 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all versions up to, and including, 9.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (8.6) | 0.34% | — | Acymailing Smtp NewsletterAI | 1/10/2026 | 1/10/2026 | Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions. | |
| Aplazada | Media (5.3) | 0.32% | — | THE NewsletterAI | 1/10/2026 | 1/10/2026 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 The plugin's public click-tracking REST route `/tnp/l/` is registered with `permission_callback => '__return_true'` and, upon receiving a valid… | |
| Aplazada | Media (4.3) | 0.25% | — | Omnisend Newsletters Email Marketing SMS AND PopupsAI | 30/9/2026 | 30/9/2026 | Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions. | |
| Aplazada | Crítica (9) | 0.46% | — | Acymailing Smtp NewsletterAI | 30/9/2026 | 30/9/2026 | Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions. | |
| Aplazada | Media (5.5) | 0.25% | — | Softnews Media Group Datalife EngineAI | 23/9/2026 | 24/9/2026 | A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. The manipulation of the argument story leads to sql injection. The attack can be initiated remotely. The exploit is publicly available… | |
| Aplazada | Media (6.5) | 0.19% | — | NewslettersAI | 23/9/2026 | 23/9/2026 | The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscriber's personal data and overwrite any subscriber's record including their email… | |
| Aplazada | Media (5.2) | 0.23% | — | Cutephp CutenewsAI | 21/9/2026 | 22/9/2026 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in the context of an authenticated user's session via a javascript: URI rendered as an unsanitized clickable link on the msg_info page. | |
| Aplazada | Media (5.8) | 0.21% | — | Cutephp CutenewsAI | 21/9/2026 | 25/9/2026 | Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __referer) via a crafted base64-encoded serialized PHP payload submitted as a POST parameter. | |
| Aplazada | Media (5.8) | 0.22% | — | Cutephp CutenewsAI | 21/9/2026 | 22/9/2026 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during POST messages to index.php. | |
| Aplazada | Crítica (9.1) | 0.27% | — | Cutephp CutenewsAI | 21/9/2026 | 24/9/2026 | CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality). | |
| Aplazada | Media (6.1) | 0.34% | — | Cutephp CutenewsAI | 21/9/2026 | 22/9/2026 | Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as "><script>alert(1)</script>). | |
| Aplazada | Alta (7.2) | 0.53% | — | Cutephp CutenewsAI | 21/9/2026 | 22/9/2026 | Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell. | |
| Aplazada | Media (6.1) | 0.38% | — | NewsletterAI | 18/9/2026 | 18/9/2026 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nn' parameter in all versions up to, and including, 9.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (7.6) | 0.38% | — | NewslettersAI | 17/9/2026 | 19/9/2026 | Administrator SQL Injection in Newsletters <= 4.18 versions. | |
| Aplazada | Media (4.8) | 0.15% | — | NewsletterAI | 17/9/2026 | 18/9/2026 | The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline to forge tracking links, obtain any subscriber's session token, and read and modify… | |
| Aplazada | Media (5.3) | 0.32% | — | NewsletterAI | 16/9/2026 | 17/9/2026 | The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect users to arbitrary external sites and to disclose a subscriber token that grants access to that subscriber record's front-end… | |
| Aplazada | Media (6.5) | 0.45% | — | E-goi Smart Marketing SMS AND Newsletters FormsAI | 12/9/2026 | 14/9/2026 | The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.51% | — | Jegstudio Gutenverse NewsAI | 11/9/2026 | 11/9/2026 | The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users to store JavaScript that will execute in… | |
| Aplazada | Media (6.5) | 0.33% | — | Blog Studio Email Subscribers AND NewslettersAI | 7/9/2026 | 8/9/2026 | The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly… | |
| Aplazada | Crítica (10) | 0.52% | — | Silk Themes Newspapers XAI | 31/8/2026 | 1/9/2026 | Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Smart Marketing SMS AND Newsletters FormsAI | 31/8/2026 | 2/9/2026 | Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Email Subscribers AND NewslettersAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions. | |
| Aplazada | Media (5.4) | 0.09% | — | NewslettersAI | 29/8/2026 | 31/8/2026 | The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted parameter into its own options, allowing attackers to make a logged in administrator overwrite arbitrary Newsletters WordPress plugin before 4.17 settings,… |