VendorsKiboko Labsarigato_autoresponder_and_newsletterany version
Vulnerabilities

Kiboko Labs Arigato Autoresponder and Newsletter any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2023-47686
WordPress Arigato Autoresponder and Newsletter Plugin <= 2.7.2.2 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-11-16 · Modified
8.8EPSS 0.003
CVE-2023-25020
WordPress Arigato Autoresponder and Newsletter Plugin <= 2.7.1.1 is vulnerable to Cross Site Scripting (XSS)
Published 2023-04-07 · Modified
7.1EPSS 0.004
CVE-2023-25061
WordPress Arigato Autoresponder and Newsletter Plugin <= 2.7.1.1 is vulnerable to Cross Site Scripting (XSS)
Published 2023-04-07 · Modified
6.5EPSS 0.004
CVE-2023-25031
WordPress Arigato Autoresponder and Newsletter Plugin <= 2.7.1 is vulnerable to Cross Site Scripting (XSS)
Published 2023-04-07 · Modified
5.9EPSS 0.004
CVE-2018-1002005
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter.
Published 2018-12-03 · Modified
4.81 PoCEPSS 0.031
CVE-2018-1002006
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST request variable classes
Published 2018-12-03 · Modified
4.81 PoCEPSS 0.026
CVE-2023-0543
Arigato Autoresponder and Newsletter < 2.1.7.2 - Admin+ Stored XSS
Published 2023-02-27 · Modified
4.8EPSS 0.005