Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sendpress CRITICAL 9.8
CVE-2023-35040

Missing Authorization vulnerability in SendPress SendPress Newsletters.This issue affects SendPress Newsletters: from n/a through 1.23.11.6.

Fix: after 1.23.11.6
Fix from $2,300 2024-06-14
Sendpress MEDIUM 6.8
CVE-2024-1588

The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege user…

Fix: after 1.23.11.6
Fix from $1,600 2024-04-08
Sendpress MEDIUM 6.1
CVE-2024-1589

The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege user…

Fix: after 1.23.11.6
Fix from $1,600 2024-04-08
Sendpress MEDIUM 6.1
CVE-2023-47517

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.23.11.6 versions.

Fix: after 1.23.11.6
Fix from $1,600 2023-11-14
Sendpress MEDIUM 5.4
CVE-2023-5660

The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and …

Fix: 1.23.11.6+
Fix from $1,600 2023-11-07
Sendpress HIGH 8.8
CVE-2023-41730

Cross-Site Request Forgery (CSRF) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions.

Fix: after 1.22.3.31
Fix from $1,950 2023-10-10
Sendpress HIGH 8.8
CVE-2015-9448

The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter.

Fix: 1.2+
Fix from $1,950 2019-09-26