Icegram
by Icegram
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-43344 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Icegram allows Stored XSS.This issue affects Icegram: from n/a through 3.1.25. | ||
| CVE-2021-24941 | Med | 0.40 | 6.1 | 0.01 | Dec 21, 2021 | The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue | ||
| CVE-2024-21748 | Med | 0.28 | 4.3 | 0.00 | Jun 8, 2024 | Missing Authorization vulnerability in Icegram.This issue affects Icegram: from n/a through 3.1.21. |
- risk 0.42cvss 6.5epss 0.00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Icegram allows Stored XSS.This issue affects Icegram: from n/a through 3.1.25.
- risk 0.40cvss 6.1epss 0.01
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue
- risk 0.28cvss 4.3epss 0.00
Missing Authorization vulnerability in Icegram.This issue affects Icegram: from n/a through 3.1.21.