Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High0
Medium3
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2025-01-08

CVE-2023-2472 - Email Marketing And Subscribe Forms By Sendinblue Plugin

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Email Marketing And Subscribe Forms By Sendinblue

CVE-2023-2472

MEDIUM CVSS 6.1 2023-06-05
Scroll to top