Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
icegram icegram vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2021-24941
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin prior to 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue
Icegram Icegram
4.3
CVSSv2
CVE-2016-10962
The icegram plugin prior to 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
Icegram Icegram Engage
4.3
CVSSv2
CVE-2016-10963
The icegram plugin prior to 1.9.19 for WordPress has XSS.
Icegram Icegram Engage
NA
CVE-2023-5414
The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level malicious users to read the contents of arbitrary files on the server, which can contain sensitive...
Icegram Icegram Express
NA
CVE-2023-52119
Cross-Site Request Forgery (CSRF) vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building:...
Icegram Icegram Engage
NA
CVE-2023-51532
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building allows Stored XSS.This issue affects Icegram Engage –...
Icegram Icegram Engage
NA
CVE-2022-45810
Improper Neutralization of Formula Elements in a CSV File vulnerability in Icegram Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce.This issue affects Icegram Express – Email Marketing, Newsletters and Automation for WordPr...
Icegram Icegram Express
NA
CVE-2023-25024
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Icegram Icegram Collect plugin <= 1.3.8 versions.
Icegram Icegram Collect
3.5
CVSSv2
CVE-2021-36832
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.
Icegram Icegram Engage
NA
CVE-2023-2398
The Icegram Engage WordPress plugin prior to 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Icegram Icegram Engage
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
encryption
CVE-2024-4331
CVE-2024-26925
arbitrary code
CVE-2006-4304
CVE-2024-25458
CVE-2024-27077
reflected XSS
CVE-2024-4059
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »