Vulnerabilities > Eelv Newsletter Project > Eelv Newsletter > 4.1.2

DATE CVE VULNERABILITY TITLE RISK
2019-08-20 CVE-2017-18523 Cross-Site Request Forgery (CSRF) vulnerability in Eelv Newsletter Project Eelv Newsletter
The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book.
6.8
2019-08-20 CVE-2017-18522 Cross-site Scripting vulnerability in Eelv Newsletter Project Eelv Newsletter
The eelv-newsletter plugin before 4.6.1 for WordPress has XSS in the address book.
4.3