Filtered by vendor Tribulant
Subscriptions
Filtered by product Newsletters
Subscriptions
Total
6 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-37227 | 1 Tribulant | 1 Newsletters | 2024-06-24 | 8.8 High |
Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7. | ||||
CVE-2023-4797 | 1 Tribulant | 1 Newsletters | 2024-01-23 | 7.2 High |
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server. | ||||
CVE-2023-30478 | 1 Tribulant | 1 Newsletters | 2023-11-15 | 8.8 High |
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions. | ||||
CVE-2019-14788 | 1 Tribulant | 1 Newsletters | 2023-05-18 | 8.8 High |
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value. | ||||
CVE-2019-14787 | 1 Tribulant | 1 Newsletters | 2023-02-24 | 5.4 Medium |
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter. | ||||
CVE-2018-20987 | 1 Tribulant | 1 Newsletters | 2019-08-23 | N/A |
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. |
Page 1 of 1.