Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
Docs
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
active newsletter vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2007-1696
SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and previous versions allows remote malicious users to execute arbitrary SQL commands via the NewsPaperID parameter.
Active Web Softwares Active Newsletter
1 EDB exploit
7.5
CVSSv2
CVE-2008-6286
Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote malicious users to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the password parameter (aka password field), to (a) Subscriber....
Activewebsoftwares Active Newsletter 4.3
1 EDB exploit
6.1
CVSSv3
CVE-2023-2472
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin prior to 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site...
Unknown Newsletter, Smtp, Email Marketing And Subscribe Forms By Sendinblue
Brevo Newsletter, Smtp, Email Marketing And Subscribe
9.8
CVSSv3
CVE-2023-47308
In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions. The method `NewsletterpopsendVerificationModuleFrontController::checkEmailSubscr...
Prestashop Newsletter Popup Pro
Activedesign Newsletterpop
6.9
CVSSv4
CVE-2025-32378
Shopware is an open source e-commerce software platform. before 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolicited newsletter sign-ups without confirmation. Default settings are Newsletter: Double Opt-in set to active, Newsletter: Double opt-i...
Shopware Shopware
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
CVE-2025-3248
thanhtungtnt
remote code execution
codepen embed block
CVE-2025-6354
chris coyier
CVE-2025-50025
nitin yawalkar
code execution
CVE-2025-50038
CVE-2023-0386
cross-site scripting
CVE-2025-6351
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started