Show filters
193 Total Results
Displaying 31-40 of 193
Sort by:
Attacker Value
Unknown
CVE-2024-6172
Disclosure Date: July 02, 2024 (last updated July 04, 2024)
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown
CVE-2024-37252
Disclosure Date: June 26, 2024 (last updated June 26, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25.
0
Attacker Value
Unknown
CVE-2024-37098
Disclosure Date: June 26, 2024 (last updated June 26, 2024)
Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.6.
0
Attacker Value
Unknown
CVE-2024-37227
Disclosure Date: June 21, 2024 (last updated June 25, 2024)
Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7.
0
Attacker Value
Unknown
CVE-2024-3961
Disclosure Date: June 21, 2024 (last updated July 18, 2024)
The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tag_subscriber function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to subscribe users to tags. Financial damages may occur to site owners if their API quota is exceeded.
0
Attacker Value
Unknown
CVE-2024-3961
Disclosure Date: June 21, 2024 (last updated July 18, 2024)
The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tag_subscriber function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to subscribe users to tags. Financial damages may occur to site owners if their API quota is exceeded.
0
Attacker Value
Unknown
CVE-2023-35040
Disclosure Date: June 14, 2024 (last updated June 14, 2024)
Missing Authorization vulnerability in SendPress SendPress Newsletters.This issue affects SendPress Newsletters: from n/a through 1.23.11.6.
0
Attacker Value
Unknown
CVE-2024-5674
Disclosure Date: June 12, 2024 (last updated July 23, 2024)
The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PHP type juggling issue on the check_api_key function in all versions up to, and including, 2.4.5. This makes it possible for unauthenticated attackers to list, create or delete newsletter subscribers. This issue affects only sites running the PHP version below 8.0
0
Attacker Value
Unknown
CVE-2024-31352
Disclosure Date: June 09, 2024 (last updated September 26, 2024)
Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13.
0
Attacker Value
Unknown
CVE-2024-35718
Disclosure Date: June 08, 2024 (last updated August 30, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS.This issue affects Newsletters: from n/a through 4.9.5.
0