Vulnerabilities (CVE)

Filtered by vendor Ibericode Subscribe
Total 6 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-6243 1 Ibericode 1 Html Forms 2024-07-25 N/A 4.8 MEDIUM
The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.
CVE-2023-32517 1 Ibericode 1 Mailchimp 2024-01-05 N/A 6.1 MEDIUM
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder.This issue affects MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder: from n/a through 4.0.9.3.
CVE-2023-50836 1 Ibericode 1 Html Forms 2024-01-04 N/A 4.8 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ibericode HTML Forms allows Stored XSS.This issue affects HTML Forms: from n/a through 1.3.28.
CVE-2022-3689 1 Ibericode 1 Html Forms 2023-11-07 N/A 7.2 HIGH
The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users
CVE-2017-18577 1 Ibericode 1 Mailchimp 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.
CVE-2016-10871 1 Ibericode 1 Mailchimp 2019-08-16 4.3 MEDIUM 6.1 MEDIUM
The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.