Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown

CVE-2023-52119

Disclosure Date: January 05, 2024 (last updated January 12, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building: from n/a through 3.1.18.
Attacker Value
Unknown

CVE-2022-45810

Disclosure Date: November 07, 2023 (last updated November 15, 2023)
Improper Neutralization of Formula Elements in a CSV File vulnerability in Icegram Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce.This issue affects Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce: from n/a through 5.5.2.
Attacker Value
Unknown

CVE-2023-5414

Disclosure Date: October 20, 2023 (last updated October 27, 2023)
The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information including those belonging to other sites, for example in shared hosting environments.
Attacker Value
Unknown

CVE-2023-2398

Disclosure Date: June 12, 2023 (last updated October 08, 2023)
The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Attacker Value
Unknown

CVE-2023-25024

Disclosure Date: April 07, 2023 (last updated November 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Icegram Icegram Collect plugin <= 1.3.8 versions.
Attacker Value
Unknown

CVE-2021-24941

Disclosure Date: December 21, 2021 (last updated February 23, 2025)
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2021-36832

Disclosure Date: August 17, 2021 (last updated February 23, 2025)
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.
Attacker Value
Unknown

CVE-2016-10963

Disclosure Date: September 16, 2019 (last updated January 11, 2024)
The icegram plugin before 1.9.19 for WordPress has XSS.
Attacker Value
Unknown

CVE-2016-10962

Disclosure Date: September 16, 2019 (last updated January 11, 2024)
The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
Attacker Value
Unknown

CVE-2019-15830

Disclosure Date: August 30, 2019 (last updated January 11, 2024)
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.
0