Search Results (26 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-24941 1 Icegram 1 Icegram 2024-11-21 6.1 Medium
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue
CVE-2019-15830 1 Icegram 1 Icegram Engage 2024-11-21 N/A
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.
CVE-2016-10963 1 Icegram 1 Icegram Engage 2024-11-21 6.1 Medium
The icegram plugin before 1.9.19 for WordPress has XSS.
CVE-2016-10962 1 Icegram 1 Icegram Engage 2024-11-21 6.5 Medium
The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
CVE-2024-39625 1 Icegram 1 Icegram 2024-11-01 5.3 Medium
Missing Authorization vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Icegram: from n/a through 3.1.24.
CVE-2024-43272 1 Icegram 1 Icegram 2024-08-19 5.3 Medium
Missing Authentication for Critical Function vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Icegram: from n/a through 3.1.24.