| CVE-2025-48301 | WordPress SMTP for SendGrid – YaySMTP plugin <= 1.5 - SQL Injection Vulnerability | YayCommerce | SMTP for SendGrid – YaySMTP | High | 7.6 | 2025-07-16 10:36:53 | Deep Dive |
| CVE-2025-54043 | WordPress SMTP for Amazon SES plugin <= 1.9 - SQL Injection Vulnerability | YayCommerce | SMTP for Amazon SES | High | 7.6 | 2025-07-16 10:36:51 | Deep Dive |
| CVE-2025-7451 | Hgiga|iSherlock - OS Command Injection | Hgiga | iSherlock-maillog-4.5 | Critical | 9.8 | 2025-07-14 02:35:40 | Deep Dive |
| CVE-2025-28974 | WordPress Free WP Mail SMTP plugin <= 1.0 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability | mail250 | Free WP Mail SMTP | High | 7.1 | 2025-06-06 12:54:32 | Deep Dive |
| CVE-2025-1123 | Solid Mail – SMTP email and logging made by SolidWP <= 2.1.5 - Unauthenticated Stored Cross-Site Scripting via Email | solidwp | Solid Mail – SMTP email and logging made by SolidWP | High | 7.2 | 2025-05-23 12:22:55 | Deep Dive |
| CVE-2025-31015 | WordPress SMTP Service, Email Delivery Solved! — MailHawk plugin <= 1.3.1 - Local File Inclusion Vulnerability | Adrian Tobey | WordPress SMTP Service, Email Delivery Solved! — MailHawk | High | 7.5 | 2025-04-11 08:42:49 | Deep Dive |
| CVE-2025-3434 | SMTP for Amazon SES – YaySMTP <= 1.8 - Unauthenticated Stored Cross-Site Scripting via Email Logs | yaycommerce | SMTP for Amazon SES – YaySMTP | High | 7.2 | 2025-04-11 08:21:32 | Deep Dive |
| CVE-2024-11273 | Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS | Unknown | Contact Form & SMTP Plugin for WordPress by PirateForms | 中危 | - | 2025-03-25 06:00:10 | Deep Dive |
| CVE-2024-11272 | Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS | Unknown | Contact Form & SMTP Plugin for WordPress by PirateForms | 中危 | - | 2025-03-25 06:00:10 | Deep Dive |
| CVE-2024-13908 | SMTP by BestWebSoft <= 1.1.9 - Authenticated (Administrator+) Arbitrary File Upload | bestweblayout | SMTP by BestWebSoft | High | 7.2 | 2025-03-08 07:04:55 | Deep Dive |
| CVE-2024-13844 | Post SMTP <= 3.1.2 - Authenticated (Administrator+) SQL Injection via columns Parameter | saadiqbal | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | Medium | 4.9 | 2025-03-08 05:30:08 | Deep Dive |
| CVE-2025-1319 | Site Mailer <= 1.2.3 - Unauthenticated Stored Cross-Site Scripting | elemntor | Site Mailer – SMTP Replacement, Email API Deliverability & Email Log | High | 7.2 | 2025-02-28 12:44:05 | Deep Dive |
| CVE-2025-0957 | Vulnerability: SMTP for Amazon SES <= 1.8 - Unauthenticated Stored Cross-Site Scripting via Email Logs | yaycommerce | SMTP for Amazon SES – YaySMTP | High | 7.2 | 2025-02-22 13:45:13 | Deep Dive |
| CVE-2025-0953 | SMTP for Sendinblue – YaySMTP <= 1.2 - Unauthenticated Stored Cross-Site Scripting via Email Logs | yaycommerce | SMTP for Sendinblue – YaySMTP | High | 7.2 | 2025-02-22 12:39:22 | Deep Dive |
| CVE-2025-0918 | SMTP for SendGrid – YaySMTP <= 1.4 - Unauthenticated Stored Cross-Site Scripting via Email Logs | yaycommerce | SMTP for SendGrid – YaySMTP | High | 7.2 | 2025-02-22 12:39:21 | Deep Dive |
| CVE-2025-0916 | YaySMTP 2.4.9 - 2.6.2 - Unauthenticated Stored Cross-Site Scripting | yaycommerce | YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service | High | 7.2 | 2025-02-19 11:10:38 | Deep Dive |
| CVE-2025-0521 | Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting | saadiqbal | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | High | 7.2 | 2025-02-18 11:10:19 | Deep Dive |
| CVE-2025-24617 | WordPress AcyMailing Plugin < 9.11.1 - Reflected Cross Site Scripting (XSS) vulnerability | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | High | 7.1 | 2025-02-14 12:44:35 | Deep Dive |
| CVE-2024-13453 | Contact Form & SMTP Plugin for WordPress by PirateForms <= 2.6.0 - Unauthenticated Arbitrary Shortcode Execution | smub | Contact Form & SMTP Plugin for WordPress by PirateForms | High | 7.3 | 2025-01-30 11:10:20 | Deep Dive |
| CVE-2025-23453 | WordPress Stars SMTP Mailer plugin <= 1.7 - Reflected Cross Site Scripting (XSS) vulnerability | Myriad Solutionz | Stars SMTP Mailer | High | 7.1 | 2025-01-16 20:05:58 | Deep Dive |