Vulnerabilities > Activecampaign > Activecampaign > 7.1.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-04-15 | CVE-2024-32430 | Unspecified vulnerability in Activecampaign Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8.1.14. | 9.8 |
2023-05-15 | CVE-2023-0233 | Unspecified vulnerability in Activecampaign The ActiveCampaign WordPress plugin before 8.1.12 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | 5.4 |
2021-03-18 | CVE-2021-24133 | Cross-Site Request Forgery (CSRF) vulnerability in Activecampaign Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could allow attacker to make a logged-in administrator change API Credentials to attacker's account. | 4.3 |