CVE-2025-24598
- EPSS 0.04%
- Veröffentlicht 04.02.2025 15:15:23
- Zuletzt bearbeitet 11.02.2025 19:37:53
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster allows Reflected XSS. This issue affects WP Mailster: from n/a through 1.8.17.0.
CVE-2025-24559
- EPSS 0.04%
- Veröffentlicht 03.02.2025 15:15:25
- Zuletzt bearbeitet 11.02.2025 19:37:35
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster allows Reflected XSS. This issue affects WP Mailster: from n/a through 1.8.15.0.
CVE-2025-22303
- EPSS 0.12%
- Veröffentlicht 07.01.2025 11:15:14
- Zuletzt bearbeitet 11.02.2025 19:37:15
Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n/a through 1.8.17.0.
CVE-2024-54355
- EPSS 0.04%
- Veröffentlicht 16.12.2024 15:15:08
- Zuletzt bearbeitet 07.02.2025 21:15:55
Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster allows Cross Site Request Forgery.This issue affects WP Mailster: from n/a through 1.8.17.0.
CVE-2024-53807
- EPSS 0.25%
- Veröffentlicht 06.12.2024 14:15:23
- Zuletzt bearbeitet 07.02.2025 21:23:25
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in brandtoss WP Mailster allows Blind SQL Injection.This issue affects WP Mailster: from n/a through 1.8.16.0.
CVE-2024-53803
- EPSS 0.32%
- Veröffentlicht 06.12.2024 14:15:22
- Zuletzt bearbeitet 10.02.2025 16:24:56
Missing Authorization vulnerability in brandtoss WP Mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.8.16.0.
CVE-2024-53804
- EPSS 0.32%
- Veröffentlicht 06.12.2024 14:15:22
- Zuletzt bearbeitet 11.02.2025 17:39:11
Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n/a through 1.8.16.0.
CVE-2024-53805
- EPSS 0.41%
- Veröffentlicht 06.12.2024 14:15:22
- Zuletzt bearbeitet 11.02.2025 17:36:03
Missing Authorization vulnerability in brandtoss WP Mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.8.16.0.
CVE-2024-11782
- EPSS 0.08%
- Veröffentlicht 03.12.2024 10:15:05
- Zuletzt bearbeitet 10.02.2025 18:10:42
The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' shortcode in all versions up to, and including, 1.8.17.0 due to insufficient input sanitization and output escaping on user supplied at...
CVE-2024-53737
- EPSS 0.06%
- Veröffentlicht 28.11.2024 11:15:54
- Zuletzt bearbeitet 10.02.2025 18:22:34
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Mailster allows Stored XSS.This issue affects WP Mailster: from n/a through 1.8.16.0.