Search Results (29 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-11924 1 Icegram 1 Icegram Express 2025-04-29 3.5 Low
The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2023-25024 1 Icegram 1 Icegram Collect 2025-01-10 5.9 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Icegram Icegram Collect plugin <= 1.3.8 versions.
CVE-2023-2398 1 Icegram 1 Icegram Engage 2025-01-03 6.1 Medium
The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-21748 1 Icegram 1 Icegram Express 2024-11-21 4.3 Medium
Missing Authorization vulnerability in Icegram.This issue affects Icegram: from n/a through 3.1.21.
CVE-2021-36832 1 Icegram 1 Icegram Engage 2024-11-21 4.8 Medium
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.
CVE-2021-24941 1 Icegram 1 Icegram 2024-11-21 6.1 Medium
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue
CVE-2019-15830 1 Icegram 1 Icegram Engage 2024-11-21 N/A
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.
CVE-2016-10963 1 Icegram 1 Icegram Engage 2024-11-21 6.1 Medium
The icegram plugin before 1.9.19 for WordPress has XSS.
CVE-2016-10962 1 Icegram 1 Icegram Engage 2024-11-21 6.5 Medium
The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.