Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.21% | — | Jegtheme Jnews VideoAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews - Video jnews-video allows Reflected XSS.This issue affects JNews - Video: from n/a through <= 11.0.2. | |
| Aplazada | Alta (7.5) | 0.47% | — | Jegtheme Jnews - PAY WriterAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jegtheme JNews - Pay Writer jnews-pay-writer allows PHP Local File Inclusion.This issue affects JNews - Pay Writer: from n/a through <= 11.0.0. | |
| Aplazada | Alta (7.1) | 0.22% | — | Jegtheme Jnews Frontend SubmitAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews - Frontend Submit jnews-frontend-submit allows Reflected XSS.This issue affects JNews - Frontend Submit: from n/a through <= 11.0.0. | |
| Aplazada | Media (4.3) | 0.12% | — | Jegtheme Jnews PaywallAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in jegtheme JNews Paywall jnews-paywall allows Cross Site Request Forgery.This issue affects JNews Paywall: from n/a through < 12.0.1. | |
| Aplazada | Media (6.5) | 0.20% | — | Jegtheme Jnews GalleryAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews Gallery jnews-gallery allows Stored XSS.This issue affects JNews Gallery: from n/a through < 12.0.1. | |
| Aplazada | Media (5.3) | 0.26% | — | Jegtheme JnewsAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in jegtheme JNews jnews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JNews: from n/a through <= 11.6.16. | |
| Aplazada | Media (5.3) | 0.28% | — | JnewsAI | 5/3/2025 | 17/6/2026 | The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 11.6.6. This is due to the plugin not properly validate if the user can register option is enabled prior to creating a user though the register_handler()… | |
| Modificada | Media (6.1) | 2.0% | — | Jnews | 7/6/2021 | 17/6/2026 | The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue. | |
| Modificada | Alta (7.2) | 0.98% | — | Joobi Jnews | 9/3/2020 | 17/6/2026 | JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field. | |
| Modificada | Alta (8.8) | 1.1% | — | Joobi Jnews | 9/3/2020 | 17/6/2026 | JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension. | |
| Modificada | Media (4.8) | 0.54% | — | Joobi Jnews | 9/3/2020 | 17/6/2026 | JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter. | |
| Modificada | Media (4.3) | 6.3% | — | Caseproof PrettylinksJoobi COM JnewsCivicrm | 12/3/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3, allows remote attackers to inject… | |
| Modificada | Media (5) | 1.5% | — | Joobi COM Jnews | 13/8/2012 | 16/6/2026 | The jNews (com_jnews) component 7.5.1 for Joomla! allows remote attackers to obtain sensitive information via the emailsearch parameter, which reveals the installation path in an error message. | |
| Modificada | Media (6.8) | 1.6% | — | Emultisoft COM Jnewspaper | 19/5/2010 | 16/6/2026 | SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the date_info parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Alta (7.5) | 1.8% | — | Emultisoft COM Jnewspaper | 19/5/2010 | 16/6/2026 | SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. NOTE: some of these details are obtained from third party information. |