Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2025-4857 The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.9.9 via the 'file' parameter. Th… Newsletters 4.10+ Fix from $1,9502025-05-31 MEDIUM 6.1 CVE-2024-13739 The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versions up to, and including, 4.9… Newsletters 4.9.9.8+ Fix from $1,6002025-03-22 MEDIUM 6.4 CVE-2024-10181 The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's newsletters_video shortcode in all versions up to,… Newsletters 4.9.9.5+ Fix from $1,6002024-10-29 HIGH 8.8 CVE-2024-8247 The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin n… Newsletters 4.9.9.3+ Fix from $1,9502024-09-06 HIGH 8.8 CVE-2024-37227 Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7. Newsletters 4.9.8+ Fix from $1,9502024-06-21 MEDIUM 6.1 CVE-2024-35718 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected X… Newsletters 4.9.6+ Fix from $1,6002024-06-08 MEDIUM 5.3 CVE-2024-31353 Insertion of Sensitive Information into Log File vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through … Slideshow Gallery 1.7.8+ Fix from $1,6002024-04-10 HIGH 7.2 CVE-2023-4797 The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell com… Newsletters 4.9.3+ Fix from $1,9502024-01-16 HIGH 7.2 CVE-2023-28491 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slideshow Gallery LITE.This issue aff… Slideshow Gallery after 1.7.6 Fix from $1,9502023-12-20 HIGH 8.8 CVE-2023-28497 Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Slideshow Gallery LITE plugin <= 1.7.6 versions. Slideshow Gallery after 1.7.6 Fix from $1,9502023-11-12 HIGH 8.8 CVE-2023-30478 Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions. Newsletters after 4.8.8 Fix from $1,9502023-11-10 HIGH 8.8 CVE-2020-35932 Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as s… Newsletter 6.8.2+ Fix from $1,9502021-01-01 HIGH 8.8 CVE-2019-15828 The one-click-ssl plugin before 1.4.7 for WordPress has CSRF. One Click Ssl 1.4.7+ Fix from $1,9502019-08-30 CRITICAL 9.8 CVE-2018-20987 The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. Newsletters 4.6.8.6+ Fix from $2,3002019-08-22 HIGH 8.8 CVE-2019-14788 wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal … Newsletters 4.6.19+ Fix from $1,9502019-08-15 MEDIUM 5.4 CVE-2019-14787 The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentare… Newsletters 4.6.19+ Fix from $1,6002019-08-09 CRITICAL 9.8 CVE-2018-18018 SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Ga… Slideshow Gallery No fix yet Fix from $2,3002019-04-15 MEDIUM 6.1 CVE-2018-18017 XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] … Slideshow Gallery No fix yet Fix from $1,6002019-04-15 MEDIUM 6.1 CVE-2018-18019 XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], S… Slideshow Gallery No fix yet Fix from $1,6002019-04-15 MEDIUM 6.1 CVE-2018-17946 The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated param… Slideshow Gallery 1.6.6.1+ Fix from $1,6002018-10-03 MEDIUM 6.5 CVE-2014-5460EPSS 71% Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to exec… Tibulant Slideshow Gallery after 1.4.6 Fix from $1,6002014-09-11