Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Icegram Express MEDIUM 6.1
CVE-2025-0671

The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege user…

Fix: 5.7.50+
Fix from $1,600 2025-04-25
Email Subscribers \& Newsletters MEDIUM 6.5
CVE-2024-12311

The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement,…

Fix: 5.7.44+
Fix from $1,600 2025-01-06
Icegram Engage MEDIUM 6.1
CVE-2024-12302

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to…

Fix: 3.1.32+
Fix from $1,600 2025-01-06
Email Subscribers \& Newsletters MEDIUM 6.3
CVE-2024-8254

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to…

Fix: 5.7.35+
Fix from $1,600 2024-10-02
Email Subscribers \& Newsletters CRITICAL 9.8
CVE-2024-6172

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to…

Fix: 5.7.26+
Fix from $2,300 2024-07-02
Icegram Express CRITICAL 9.8
CVE-2024-5756

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to…

Fix: 5.7.24+
Fix from $2,300 2024-06-21
Icegram Express HIGH 8.8
CVE-2024-4845

The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all versions up to, and including, 5.…

Fix: 5.7.23+
Fix from $1,950 2024-06-12
Email Subscribers \& Newsletters CRITICAL 9.8
CVE-2024-31352

Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13.

Fix: 5.7.14+
Fix from $2,300 2024-06-09
Icegram Express MEDIUM 5.4
CVE-2024-21748

Missing Authorization vulnerability in Icegram.This issue affects Icegram: from n/a through 3.1.21.

Fix: 3.1.22+
Fix from $1,600 2024-06-08
Email Subscribers \& Newsletters CRITICAL 9.8
CVE-2024-4295EPSS 10%

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and incl…

Fix: 5.7.21+
Fix from $2,300 2024-06-05
Icegram Engage MEDIUM 5.4
CVE-2023-51532

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Icegram Engage – WordPress Lead Generat…

Fix: after 3.1.19
Fix from $1,600 2024-02-01
Icegram Engage HIGH 8.8
CVE-2023-52119

Cross-Site Request Forgery (CSRF) vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Buil…

Fix: after 3.1.18
Fix from $1,950 2024-01-05
Icegram Express CRITICAL 9.8
CVE-2022-45810

Improper Neutralization of Formula Elements in a CSV File vulnerability in Icegram Icegram Express – Email Marketing, Newsletters and Automation for …

Fix: after 5.5.2
Fix from $2,300 2023-11-07
Icegram Express HIGH 7.2
CVE-2023-5414

The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function.…

Fix: after 5.6.23
Fix from $1,950 2023-10-20
Icegram Engage MEDIUM 6.1
CVE-2023-2398

The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross…

Fix: 3.1.12+
Fix from $1,600 2023-06-12
Email Subscribers \& Newsletters HIGH 8.8
CVE-2022-3981

The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a …

Fix: 5.5.1+
Fix from $1,950 2022-12-12
Popups\, Welcome Bar\, Optins And Lead Generation Plugin MEDIUM 5.4
CVE-2022-1776

The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which…

Fix: 2.1.8+
Fix from $1,600 2022-06-27
Email Subscribers \& Newsletters HIGH 8.8
CVE-2022-0439

The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_r…

Fix: 5.3.2+
Fix from $1,950 2022-03-07
Icegram MEDIUM 6.1
CVE-2021-24941

The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the…

Fix: 2.0.5+
Fix from $1,600 2021-12-21
Icegram Engage MEDIUM 5.4
CVE-2021-36832

WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline])…

Fix: after 2.0.2
Fix from $1,600 2021-10-19
Email Subscribers \& Newsletters MEDIUM 5.3
CVE-2020-5780

Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, …

Fix: 4.5.6+
Fix from $1,600 2020-09-10
Email Subscribers \& Newsletters MEDIUM 6.5
CVE-2020-5767

Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by t…

No fix yet
Fix from $1,600 2020-07-17
Email Subscribers \& Newsletters CRITICAL 9.8
CVE-2019-20361EPSS 85%

There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in t…

Fix: 4.3.1+
Fix from $2,300 2020-01-08
Email Subscribers \& Newsletters MEDIUM 6.3
CVE-2019-19984

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settin…

Fix: 4.2.3+
Fix from $1,600 2019-12-26
Email Subscribers \& Newsletters MEDIUM 5.4
CVE-2019-19981

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.

Fix: 4.2.3+
Fix from $1,600 2019-12-26
Email Subscribers \& Newsletters MEDIUM 5.3
CVE-2019-19982

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit …

Fix: 4.2.3+
Fix from $1,600 2019-12-26
Email Subscribers \& Newsletters MEDIUM 5.3
CVE-2019-19985EPSS 71%

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information discl…

Fix: 4.2.3+
Fix from $1,600 2019-12-26
Icegram Engage MEDIUM 6.5
CVE-2016-10962

The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.

Fix: 1.9.19+
Fix from $1,600 2019-09-16
Icegram Engage MEDIUM 6.1
CVE-2016-10963

The icegram plugin before 1.9.19 for WordPress has XSS.

Fix: 1.9.19+
Fix from $1,600 2019-09-16
Icegram Engage MEDIUM 5.4
CVE-2019-15830

The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.

Fix: 1.10.29+
Fix from $1,600 2019-08-30