Icegram

Icegram Engage

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Veröffentlicht 15.05.2025 20:15:39
  • Zuletzt bearbeitet 28.05.2025 15:42:41

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disa...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 15.05.2025 20:15:39
  • Zuletzt bearbeitet 28.05.2025 15:42:32

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disa...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 06.01.2025 06:15:06
  • Zuletzt bearbeitet 14.05.2025 14:14:28

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks

  • EPSS 0.08%
  • Veröffentlicht 01.02.2024 11:15:08
  • Zuletzt bearbeitet 21.11.2024 08:38:19

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building allows Stored XSS.This issue affects Icegram ...

  • EPSS 0.09%
  • Veröffentlicht 05.01.2024 10:15:12
  • Zuletzt bearbeitet 21.11.2024 08:39:13

Cross-Site Request Forgery (CSRF) vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Em...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 12.06.2023 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:58:32

The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • EPSS 0.18%
  • Veröffentlicht 19.10.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:14:10

WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.

  • EPSS 0.14%
  • Veröffentlicht 16.09.2019 13:15:10
  • Zuletzt bearbeitet 21.11.2024 02:45:10

The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.

  • EPSS 0.19%
  • Veröffentlicht 16.09.2019 13:15:10
  • Zuletzt bearbeitet 21.11.2024 02:45:10

The icegram plugin before 1.9.19 for WordPress has XSS.

  • EPSS 0.21%
  • Veröffentlicht 30.08.2019 14:15:10
  • Zuletzt bearbeitet 21.11.2024 04:29:33

The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.