Vulnerabilities > Inboundnow

DATE CVE VULNERABILITY TITLE RISK
2023-03-06 CVE-2015-10090 Cross-site Scripting vulnerability in Inboundnow Landing-Pages
A vulnerability, which was classified as problematic, has been found in Landing Pages Plugin up to 1.8.7 on WordPress.
network
low complexity
inboundnow CWE-79
6.1
2017-10-18 CVE-2015-5227 Injection vulnerability in Inboundnow Wordpress Landing Pages
The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter.
network
low complexity
inboundnow CWE-74
8.8
2017-09-11 CVE-2015-8350 Cross-site Scripting vulnerability in Inboundnow Call to Action
Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) open-tab parameter in a wp_cta_global_settings action to wp-admin/edit.php or (2) wp-cta-variation-id parameter to ab-testing-call-to-action-example/.
network
low complexity
inboundnow CWE-79
6.1