Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

1110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaCrítica (9.3)——Sendpress NewslettersAI6/10/20266/10/2026
Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions.
AplazadaAlta (7.2)0.27%—NewsletterAI2/10/20263/10/2026
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all versions up to, and including, 9.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaAlta (8.6)0.34%—Acymailing Smtp NewsletterAI1/10/20261/10/2026
Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions.
AplazadaMedia (5.3)0.32%—THE NewsletterAI1/10/20261/10/2026
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 The plugin's public click-tracking REST route `/tnp/l/` is registered with `permission_callback => '__return_true'` and, upon receiving a valid…
AplazadaMedia (4.3)0.25%—Omnisend Newsletters Email Marketing SMS AND PopupsAI30/9/202630/9/2026
Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.
AplazadaCrítica (9)0.46%—Acymailing Smtp NewsletterAI30/9/202630/9/2026
Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
AplazadaMedia (5.5)0.25%—Softnews Media Group Datalife EngineAI23/9/202624/9/2026
A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. The manipulation of the argument story leads to sql injection. The attack can be initiated remotely. The exploit is publicly available…
AplazadaMedia (6.5)0.19%—NewslettersAI23/9/202623/9/2026
The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscriber's personal data and overwrite any subscriber's record including their email…
AplazadaMedia (5.2)0.23%—Cutephp CutenewsAI21/9/202622/9/2026
CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in the context of an authenticated user's session via a javascript: URI rendered as an unsanitized clickable link on the msg_info page.
AplazadaMedia (5.8)0.21%—Cutephp CutenewsAI21/9/202625/9/2026
Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __referer) via a crafted base64-encoded serialized PHP payload submitted as a POST parameter.
AplazadaMedia (5.8)0.22%—Cutephp CutenewsAI21/9/202622/9/2026
CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during POST messages to index.php.
AplazadaCrítica (9.1)0.27%—Cutephp CutenewsAI21/9/202624/9/2026
CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality).
AplazadaMedia (6.1)0.34%—Cutephp CutenewsAI21/9/202622/9/2026
Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as "><script>alert(1)</script>).
AplazadaAlta (7.2)0.53%—Cutephp CutenewsAI21/9/202622/9/2026
Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.
AplazadaMedia (6.1)0.38%—NewsletterAI18/9/202618/9/2026
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nn' parameter in all versions up to, and including, 9.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaAlta (7.6)0.38%—NewslettersAI17/9/202619/9/2026
Administrator SQL Injection in Newsletters <= 4.18 versions.
AplazadaMedia (4.8)0.15%—NewsletterAI17/9/202618/9/2026
The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline to forge tracking links, obtain any subscriber's session token, and read and modify…
AplazadaMedia (5.3)0.32%—NewsletterAI16/9/202617/9/2026
The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect users to arbitrary external sites and to disclose a subscriber token that grants access to that subscriber record's front-end…
AplazadaMedia (6.5)0.45%—E-goi Smart Marketing SMS AND Newsletters FormsAI12/9/202614/9/2026
The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaAlta (8.8)0.51%—Jegstudio Gutenverse NewsAI11/9/202611/9/2026
The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users to store JavaScript that will execute in…
AplazadaMedia (6.5)0.33%—Blog Studio Email Subscribers AND NewslettersAI7/9/20268/9/2026
The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly…
AplazadaCrítica (10)0.52%—Silk Themes Newspapers XAI31/8/20261/9/2026
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48.
AplazadaCrítica (9.3)0.40%—Smart Marketing SMS AND Newsletters FormsAI31/8/20262/9/2026
Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.
AplazadaAlta (7.1)0.25%—Email Subscribers AND NewslettersAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.
AplazadaMedia (5.4)0.09%—NewslettersAI29/8/202631/8/2026
The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted parameter into its own options, allowing attackers to make a logged in administrator overwrite arbitrary Newsletters WordPress plugin before 4.17 settings,…