VendorsThinkShoutmailchimpall versions
Vulnerabilities

ThinkShout Mailchimp

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2012-5551
Multiple cross-site scripting (XSS) vulnerabilities in the MailChimp module 7.x-2.x before 7.x-2.7 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) a predictable "webhook URL key" and (2) improper sanitization of "Webhook variables from POST requests."
Published 2012-12-03 · Modified
4.3EPSS 0.012
CVE-2015-5488
Cross-site scripting (XSS) vulnerability in the MailChimp Signup submodule in the MailChimp module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "administer mailchimp" permission to inject arbitrary web script or HTML via unspecified vectors.
Published 2015-08-18 · Modified
2.1EPSS 0.014