Known Vulnerabilities for Email Templates by Wpexperts
Listed below are 1 of the newest known vulnerabilities associated with "Email Templates" by "Wpexperts".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56785 json | FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields... | Not Provided | 2026-06-23 | 2026-06-24 |
| CVE-2026-55792 json | Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.18.0, and 5.0.0-RC1 and ab... | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-45714 json | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerabil... | Not Provided | 2026-05-13 | 2026-05-14 |
| CVE-2026-44377 json | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerabil... | Not Provided | 2026-05-13 | 2026-05-14 |
| CVE-2026-42857 json | Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_bo... | Not Provided | 2026-05-11 | 2026-05-13 |
| CVE-2026-41951 json | Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templat... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-38432 json | ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permi... | Not Provided | 2026-05-05 | 2026-05-06 |
| CVE-2026-38431 json | ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or... | Not Provided | 2026-05-05 | 2026-05-06 |
| CVE-2026-28496 json | FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template ... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-27694 json | Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email no... | Not Provided | 2026-05-05 | 2026-05-05 |