Icegram
icegram
45 CVEs • 6 products
Products (6)
Click to collapseToggle
Products (6)
Click to collapse
CVEs (45)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross-Site Request Forgery (CSRF) vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building.This issue affects Icegram Engage – WordPress Lead Generation, Pop...Show more |
Improper Neutralization of Formula Elements in a CSV File vulnerability in Icegram Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce.This issue affects Icegram Express – Email Mark...Show more |
The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbi...Show more |
The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such a...Show more |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Icegram Icegram Collect plugin <= 1.3.8 versions. |
1Icegram 1Email Subscribers & Newsletters Apr 22, 2025 Dec 12, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribe...Show more |
1Icegram 1Popups, Welcome Bar, Optins And Lead Generation Plugin Nov 21, 2024 Jun 27, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored...Show more |
1Icegram 1Email Subscribers & Newsletters Nov 21, 2024 Mar 7, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks...Show more |
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an att...Show more |
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input. |
1Icegram 1Email Subscribers & Newsletters Nov 21, 2024 Sep 10, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoof...Show more |
1Icegram 1Email Subscribers & Newsletters Nov 21, 2024 Jul 17, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value o...Show more |
1Icegram 1Email Subscribers & Newsletters Nov 21, 2024 Jul 17, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link. |
1Icegram 1Email Subscribers & Newsletters Nov 21, 2024 Jan 8, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability). |
1Icegram 1Email Subscribers & Newsletters Nov 21, 2024 Dec 26, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure. |
1Icegram 1Email Subscribers & Newsletters Nov 21, 2024 Dec 26, 2019 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns. |
1Icegram 1Email Subscribers & Newsletters Nov 21, 2024 Dec 26, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-po...Show more |
1Icegram 1Email Subscribers & Newsletters Nov 21, 2024 Dec 26, 2019 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings. |
1Icegram 1Email Subscribers & Newsletters Nov 21, 2024 Dec 26, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on beh...Show more |
The icegram plugin before 1.9.19 for WordPress has XSS. |