VYPR

Icegram

by Icegram

CVEs (3)

  • CVE-2024-43344MedAug 18, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Icegram allows Stored XSS.This issue affects Icegram: from n/a through 3.1.25.

  • CVE-2021-24941MedDec 21, 2021
    risk 0.40cvss 6.1epss 0.01

    The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue

  • CVE-2024-21748MedJun 8, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Icegram.This issue affects Icegram: from n/a through 3.1.21.