Known Vulnerabilities for Newsletters by Contrid
Listed below are 10 of the newest known vulnerabilities associated with "Newsletters" by "Contrid".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-81756 json | Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | Not Provided | 2026-08-31 | 2026-09-02 |
| CVE-2026-81741 json | The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect ta... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-81660 json | The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape valu... | Not Provided | 2026-08-30 | 2026-08-31 |
| CVE-2026-81290 json | Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions. | Not Provided | 2026-08-31 | 2026-09-01 |
| CVE-2026-77161 json | The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name ... | Not Provided | 2026-09-12 | 2026-09-14 |
| CVE-2026-75908 json | The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This i... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-57645 json | newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions. | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-57394 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software News... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-54840 json | Unauthenticated Broken Access Control in Newsletters <= 4.13 versions. | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-18387 json | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via... | Not Provided | 2026-08-15 | 2026-08-17 |