CVE-2024-13482
- EPSS 0.06%
- Veröffentlicht 15.05.2025 20:15:39
- Zuletzt bearbeitet 28.05.2025 15:42:41
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disa...
CVE-2024-13486
- EPSS 0.06%
- Veröffentlicht 15.05.2025 20:15:39
- Zuletzt bearbeitet 28.05.2025 15:42:32
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disa...
CVE-2024-12302
- EPSS 0.15%
- Veröffentlicht 06.01.2025 06:15:06
- Zuletzt bearbeitet 14.05.2025 14:14:28
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks
CVE-2023-51532
- EPSS 0.08%
- Veröffentlicht 01.02.2024 11:15:08
- Zuletzt bearbeitet 21.11.2024 08:38:19
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building allows Stored XSS.This issue affects Icegram ...
CVE-2023-52119
- EPSS 0.09%
- Veröffentlicht 05.01.2024 10:15:12
- Zuletzt bearbeitet 21.11.2024 08:39:13
Cross-Site Request Forgery (CSRF) vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Em...
CVE-2023-2398
- EPSS 0.13%
- Veröffentlicht 12.06.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:58:32
The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2021-36832
- EPSS 0.18%
- Veröffentlicht 19.10.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:10
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.
CVE-2016-10962
- EPSS 0.14%
- Veröffentlicht 16.09.2019 13:15:10
- Zuletzt bearbeitet 21.11.2024 02:45:10
The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
CVE-2016-10963
- EPSS 0.19%
- Veröffentlicht 16.09.2019 13:15:10
- Zuletzt bearbeitet 21.11.2024 02:45:10
The icegram plugin before 1.9.19 for WordPress has XSS.
CVE-2019-15830
- EPSS 0.21%
- Veröffentlicht 30.08.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:29:33
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.