Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-01-14

CVE-2023-0233 - Activecampaign Plugin

The ActiveCampaign WordPress plugin before 8.1.12 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Activecampaign

CVE-2023-0233

MEDIUM CVSS 5.4 2023-05-15
Threat Entry Updated 2024-11-21

CVE-2021-24133 - Activecampaign Plugin

Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could allow attacker to make a logged-in administrator change API Credentials to attacker's account.

PLUGIN Activecampaign

CVE-2021-24133

MEDIUM CVSS 4.3 2021-03-18
Scroll to top