CVE-2026-13362
- EPSS 0.2%
- Veröffentlicht 01.08.2026 01:29:56
- Zuletzt bearbeitet 12.08.2026 21:00:37
The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes ...
CVE-2025-67948
- EPSS 0.25%
- Veröffentlicht 16.12.2025 08:12:57
- Zuletzt bearbeitet 15.04.2026 00:35:42
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in SendPulse SendPulse Email Marketing Newsletter sendpulse-email-marketing-newsletter allows Retrieve Embedded Sensitive Data.This issue affects SendPulse Email...
CVE-2025-47547
- EPSS 0.25%
- Veröffentlicht 07.05.2025 14:20:18
- Zuletzt bearbeitet 23.04.2026 15:30:27
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPulse Email Marketing Newsletter sendpulse-email-marketing-newsletter allows Stored XSS.This issue affects SendPulse Email Marketing N...