Known Vulnerabilities for products from Icegram

Listed below are 18 of the newest known vulnerabilities associated with the vendor "Icegram".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2025-68038 Not Provided 2025-12-24 2026-04-01
CVE-2025-47527 Not Provided 2025-06-09 2026-04-01
CVE-2025-24542 Not Provided 2025-01-24 2026-04-01
CVE-2022-0439 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 8.8 - HIGH 2022-03-07 2023-11-07
CVE-2021-36832 WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&m... 5.4 - MEDIUM 2021-10-19 2024-01-10
CVE-2021-24941 The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the mes... 6.1 - MEDIUM 2021-12-21 2021-12-27
CVE-2020-5780 Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version... 5.3 - MEDIUM 2020-09-10 2020-09-16
CVE-2020-5768 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newslette... 4.9 - MEDIUM 2020-07-17 2020-07-21
CVE-2020-5767 Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to... 6.5 - MEDIUM 2020-07-17 2020-07-21
CVE-2019-20361 There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be pas... 9.8 - CRITICAL 2020-01-08 2023-01-31
CVE-2019-19985 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download wit... 5.3 - MEDIUM 2019-12-26 2022-04-26
CVE-2019-19984 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities... 6.3 - MEDIUM 2019-12-26 2020-08-24
CVE-2019-19982 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creati... 5.3 - MEDIUM 2019-12-26 2019-12-30
CVE-2019-19981 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all p... 5.4 - MEDIUM 2019-12-26 2020-08-24
CVE-2019-19980 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated us... 4.3 - MEDIUM 2019-12-26 2020-08-24
CVE-2019-15830 The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS. 5.4 - MEDIUM 2019-08-30 2024-01-10
CVE-2019-14364 An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicio... 6.1 - MEDIUM 2019-07-28 2023-11-07
CVE-2019-13569 A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Succe... 9.8 - CRITICAL 2019-07-19 2019-07-31
CVE-2018-6015 An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST requ... 7.5 - HIGH 2018-01-26 2018-02-12
CVE-2016-10963 The icegram plugin before 1.9.19 for WordPress has XSS. 6.1 - MEDIUM 2019-09-16 2024-01-10

Known software with vulnerabilities from Icegram

Type Vendor Product Version
ApplicationIcegramEmail Subscribers Amp Newsletters1.0
ApplicationIcegramIcegram-