RSS   Vulnerabilities for 'Icegram'   RSS

2021-12-21
 
CVE-2021-24941

CWE-79
 

 
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue

 
2021-10-19
 
CVE-2021-36832

CWE-79
 

 
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin �?? Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.

 
2019-09-16
 
CVE-2016-10963

CWE-79
 

 
The icegram plugin before 1.9.19 for WordPress has XSS.

 
 
CVE-2016-10962

CWE-352
 

 
The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.

 
2019-08-30
 
CVE-2019-15830

CWE-79
 

 
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.

 

 >>> Vendor: Icegram 3 Products
Email subscribers & newsletters
Icegram
Email subscribers \& newsletters


Copyright 2024, cxsecurity.com

 

Back to Top