Show filters
62 Total Results
Displaying 31-40 of 62
Sort by:
Attacker Value
Unknown

CVE-2024-22300

Disclosure Date: March 27, 2024 (last updated April 02, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11.
0
Attacker Value
Unknown

CVE-2023-4797

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.
Attacker Value
Unknown

CVE-2023-51414

Disclosure Date: December 29, 2023 (last updated January 06, 2024)
Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email Marketing y Newsletters: from n/a through 2.1.
Attacker Value
Unknown

CVE-2023-30478

Disclosure Date: November 10, 2023 (last updated November 16, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions.
Attacker Value
Unknown

CVE-2022-3981

Disclosure Date: December 12, 2022 (last updated October 08, 2023)
The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber
Attacker Value
Unknown

CVE-2022-0439

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.
Attacker Value
Unknown

CVE-2021-34634

Disclosure Date: July 31, 2021 (last updated February 23, 2025)
The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.23.
Attacker Value
Unknown

CVE-2021-20743

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform a specific operation.
Attacker Value
Unknown

CVE-2020-5780

Disclosure Date: September 10, 2020 (last updated February 22, 2025)
Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing.
Attacker Value
Unknown

CVE-2020-5767

Disclosure Date: July 17, 2020 (last updated February 21, 2025)
Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.