Search Results (28 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-25024 1 Icegram 1 Icegram Collect 2025-01-10 5.9 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Icegram Icegram Collect plugin <= 1.3.8 versions.
CVE-2023-2398 1 Icegram 1 Icegram Engage 2025-01-03 6.1 Medium
The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-21748 1 Icegram 1 Icegram Express 2024-11-21 4.3 Medium
Missing Authorization vulnerability in Icegram.This issue affects Icegram: from n/a through 3.1.21.
CVE-2021-36832 1 Icegram 1 Icegram Engage 2024-11-21 4.8 Medium
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.
CVE-2021-24941 1 Icegram 1 Icegram 2024-11-21 6.1 Medium
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue
CVE-2019-15830 1 Icegram 1 Icegram Engage 2024-11-21 N/A
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.
CVE-2016-10963 1 Icegram 1 Icegram Engage 2024-11-21 6.1 Medium
The icegram plugin before 1.9.19 for WordPress has XSS.
CVE-2016-10962 1 Icegram 1 Icegram Engage 2024-11-21 6.5 Medium
The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.