Pressified
Pressified Sendpress: vulnerabilidades y CVE
Pressified Sendpress tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-35040 | Crítica (9.8) | 0.42% | — | 14 jun 2024 | Missing Authorization vulnerability in SendPress SendPress Newsletters.This issue affects SendPress Newsletters: from n/a through 1.23.11.6. |
| CVE-2024-1589 | Media (6.1) | 0.40% | — | 8 abr 2024 | The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even… |
| CVE-2024-1588 | Media (6.8) | 0.71% | — | 8 abr 2024 | The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even… |
| CVE-2023-47517 | Media (6.1) | 0.41% | — | 14 nov 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.23.11.6 versions. |
| CVE-2023-5660 | Media (5.4) | 0.66% | — | 7 nov 2023 | The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.22.3.31 due to insufficient input sanitization and output… |
| CVE-2023-41730 | Alta (8.8) | 0.25% | — | 10 oct 2023 | Cross-Site Request Forgery (CSRF) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions. |
| CVE-2023-41729 | Media (4.8) | 0.37% | — | 2 oct 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions. |
| CVE-2015-9448 | Alta (8.8) | 1.9% | — | 26 sept 2019 | The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter. |