Show filters
62 Total Results
Displaying 31-40 of 62
Sort by:
Attacker Value
Unknown
CVE-2024-22300
Disclosure Date: March 27, 2024 (last updated April 02, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11.
0
Attacker Value
Unknown
CVE-2023-4797
Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.
0
Attacker Value
Unknown
CVE-2023-51414
Disclosure Date: December 29, 2023 (last updated January 06, 2024)
Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email Marketing y Newsletters: from n/a through 2.1.
0
Attacker Value
Unknown
CVE-2023-30478
Disclosure Date: November 10, 2023 (last updated November 16, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions.
0
Attacker Value
Unknown
CVE-2022-3981
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber
0
Attacker Value
Unknown
CVE-2022-0439
Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.
0
Attacker Value
Unknown
CVE-2021-34634
Disclosure Date: July 31, 2021 (last updated February 23, 2025)
The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.23.
0
Attacker Value
Unknown
CVE-2021-20743
Disclosure Date: June 22, 2021 (last updated February 22, 2025)
Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform a specific operation.
0
Attacker Value
Unknown
CVE-2020-5780
Disclosure Date: September 10, 2020 (last updated February 22, 2025)
Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing.
0
Attacker Value
Unknown
CVE-2020-5767
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.
0