Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-0671 The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege user… Icegram Express 5.7.50+ Fix from $1,6002025-04-25 MEDIUM 6.5 CVE-2024-12311 The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement,… Email Subscribers \& Newsletters 5.7.44+ Fix from $1,6002025-01-06 MEDIUM 6.1 CVE-2024-12302 The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to… Icegram Engage 3.1.32+ Fix from $1,6002025-01-06 MEDIUM 6.3 CVE-2024-8254 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to… Email Subscribers \& Newsletters 5.7.35+ Fix from $1,6002024-10-02 CRITICAL 9.8 CVE-2024-6172 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to… Email Subscribers \& Newsletters 5.7.26+ Fix from $2,3002024-07-02 CRITICAL 9.8 CVE-2024-5756 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to… Icegram Express 5.7.24+ Fix from $2,3002024-06-21 HIGH 8.8 CVE-2024-4845 The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all versions up to, and including, 5.… Icegram Express 5.7.23+ Fix from $1,9502024-06-12 CRITICAL 9.8 CVE-2024-31352 Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13. Email Subscribers \& Newsletters 5.7.14+ Fix from $2,3002024-06-09 MEDIUM 5.4 CVE-2024-21748 Missing Authorization vulnerability in Icegram.This issue affects Icegram: from n/a through 3.1.21. Icegram Express 3.1.22+ Fix from $1,6002024-06-08 CRITICAL 9.8 CVE-2024-4295EPSS 10% The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and incl… Email Subscribers \& Newsletters 5.7.21+ Fix from $2,3002024-06-05 MEDIUM 5.4 CVE-2023-51532 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Icegram Engage – WordPress Lead Generat… Icegram Engage after 3.1.19 Fix from $1,6002024-02-01 HIGH 8.8 CVE-2023-52119 Cross-Site Request Forgery (CSRF) vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Buil… Icegram Engage after 3.1.18 Fix from $1,9502024-01-05 CRITICAL 9.8 CVE-2022-45810 Improper Neutralization of Formula Elements in a CSV File vulnerability in Icegram Icegram Express – Email Marketing, Newsletters and Automation for … Icegram Express after 5.5.2 Fix from $2,3002023-11-07 HIGH 7.2 CVE-2023-5414 The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function.… Icegram Express after 5.6.23 Fix from $1,9502023-10-20 MEDIUM 6.1 CVE-2023-2398 The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross… Icegram Engage 3.1.12+ Fix from $1,6002023-06-12 HIGH 8.8 CVE-2022-3981 The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a … Email Subscribers \& Newsletters 5.5.1+ Fix from $1,9502022-12-12 MEDIUM 5.4 CVE-2022-1776 The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which… Popups\, Welcome Bar\, Optins And Lead Generation Plugin 2.1.8+ Fix from $1,6002022-06-27 HIGH 8.8 CVE-2022-0439 The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_r… Email Subscribers \& Newsletters 5.3.2+ Fix from $1,9502022-03-07 MEDIUM 6.1 CVE-2021-24941 The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the… Icegram 2.0.5+ Fix from $1,6002021-12-21 MEDIUM 5.4 CVE-2021-36832 WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline])… Icegram Engage after 2.0.2 Fix from $1,6002021-10-19 MEDIUM 5.3 CVE-2020-5780 Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, … Email Subscribers \& Newsletters 4.5.6+ Fix from $1,6002020-09-10 MEDIUM 6.5 CVE-2020-5767 Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by t… Email Subscribers \& Newsletters No fix yet Fix from $1,6002020-07-17 CRITICAL 9.8 CVE-2019-20361EPSS 85% There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in t… Email Subscribers \& Newsletters 4.3.1+ Fix from $2,3002020-01-08 MEDIUM 6.3 CVE-2019-19984 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settin… Email Subscribers \& Newsletters 4.2.3+ Fix from $1,6002019-12-26 MEDIUM 5.4 CVE-2019-19981 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings. Email Subscribers \& Newsletters 4.2.3+ Fix from $1,6002019-12-26 MEDIUM 5.3 CVE-2019-19982 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit … Email Subscribers \& Newsletters 4.2.3+ Fix from $1,6002019-12-26 MEDIUM 5.3 CVE-2019-19985EPSS 71% The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information discl… Email Subscribers \& Newsletters 4.2.3+ Fix from $1,6002019-12-26 MEDIUM 6.5 CVE-2016-10962 The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter. Icegram Engage 1.9.19+ Fix from $1,6002019-09-16 MEDIUM 6.1 CVE-2016-10963 The icegram plugin before 1.9.19 for WordPress has XSS. Icegram Engage 1.9.19+ Fix from $1,6002019-09-16 MEDIUM 5.4 CVE-2019-15830 The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS. Icegram Engage 1.10.29+ Fix from $1,6002019-08-30