VendorsIcegramicegram_expressany version
Vulnerabilities

Icegram Icegram Express any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2024-5756
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.23 - Unauthenticated SQL Injection via optin
Published 2024-06-21 · Modified
9.8EPSS 0.007
CVE-2022-45810
WordPress Email Subscribers & Newsletters Plugin <= 5.5.2 is vulnerable to CSV Injection
Published 2023-11-07 · Modified
9.8EPSS 0.006
CVE-2023-5414
Icegram Express <= 5.6.23 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read
Published 2023-10-20 · Modified
9.1EPSS 0.010
CVE-2024-4845
Icegram Express <= 5.7.22 - Authenticated (Subscriber+) SQL Injection Vulnerability via options[list_id]
Published 2024-06-12 · Modified
8.8EPSS 0.005
CVE-2025-0671
Email Subscribers < 5.7.50 - Admin+ Stored XSS in Template
Published 2025-04-25 · Analyzed
6.1EPSS 0.003
CVE-2024-21748
WordPress Icegram Engage plugin <= 3.1.21 - Broken Access Control vulnerability
Published 2024-06-08 · Modified
5.4EPSS 0.003
CVE-2024-11924
Email Subscribers < 5.7.52 - Admin+ Stored XSS
Published 2025-04-17 · Analyzed
3.5EPSS 0.003