Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Arigato Autoresponder and Newsletter — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in Arigato Autoresponder and Newsletter, with AI-generated Chinese analysis, references, and POCs.

This document outlines the vulnerability aggregation details for Arigato Autoresponder and Newsletter, a product developed by Arigato Mailer, focusing on common weakness enumerations relevant to email automation systems. The page collects a comprehensive range of security issues, including cross-site scripting, remote code execution, and authentication bypasses, covering reported vulnerabilities from early 2018 through to recent disclosures in late 2023 and beyond. By utilizing this resource, researchers and system administrators can effectively track vendor advisories to stay informed about the latest patches and mitigation strategies recommended by the development team. Users can also deepen their understanding of specific weakness classes by analyzing how these flaws manifest within the application’s architecture, providing context on the severity and potential impact of each defect. Furthermore, the aggregated data allows for a thorough lookup of the product’s vulnerability history, enabling security professionals to assess the overall risk posture of their deployment environments over time. This centralized approach simplifies the process of monitoring security updates, ensuring that organizations using Arigato Autoresponder and Newsletter can maintain compliance and reduce exposure to known exploits without needing to sift through disparate sources. The information presented here serves as a critical reference point for auditing and hardening these specific mail handling applications against emerging threats.

Vendor: Kiboko Labs https://calendarscripts.info/

CVE IDTitleCVSSSeverityPublished
CVE-2025-39594 WordPress Arigato Autoresponder and Newsletter plugin <= 2.7.2.4 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2025-04-17
CVE-2024-34823 WordPress Arigato Autoresponder and Newsletter plugin <= 2.7.2.3 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium2024-05-10
CVE-2023-47686 WordPress Arigato Autoresponder and Newsletter Plugin <= 2.7.2.2 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium2023-11-16
CVE-2023-25020 WordPress Arigato Autoresponder and Newsletter Plugin <= 2.7.1.1 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High2023-04-07
CVE-2023-25031 WordPress Arigato Autoresponder and Newsletter Plugin <= 2.7.1 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.9 Medium2023-04-07
CVE-2023-25061 WordPress Arigato Autoresponder and Newsletter Plugin <= 2.7.1.1 is vulnerable to Cross Site Scripting (XSS) CWE-79 6.5 Medium2023-04-07
CVE-2023-0543 Arigato Autoresponder and Newsletter < 2.1.7.2 - Admin+ Stored XSS 4.8 -2023-02-27
CVE-2018-1002008 Wordpress Arigato Autoresponder and Newsletter 跨站脚本漏洞 4.8 -2018-12-03
CVE-2018-1002009 Wordpress Arigato Autoresponder and Newsletter 跨站脚本漏洞 4.8 -2018-12-03
CVE-2018-1002000 Wordpress Arigato Autoresponder and Newsletter SQL注入漏洞 7.2 -2018-12-03
CVE-2018-1002007 Wordpress Arigato Autoresponder and Newsletter 跨站脚本漏洞 4.8 -2018-12-03
CVE-2018-1002006 Wordpress Arigato Autoresponder and Newsletter 跨站脚本漏洞 4.8 -2018-12-03
CVE-2018-1002005 Wordpress Arigato Autoresponder and Newsletter 跨站脚本漏洞 4.8 -2018-12-03
CVE-2018-1002004 Wordpress Arigato Autoresponder and Newsletter 跨站脚本漏洞 4.8 -2018-12-03
CVE-2018-1002003 Wordpress Arigato Autoresponder and Newsletter 跨站脚本漏洞 4.8 -2018-12-03
CVE-2018-1002002 Wordpress Arigato Autoresponder and Newsletter 跨站脚本漏洞 4.8 -2018-12-03
CVE-2018-1002001 Wordpress Arigato Autoresponder and Newsletter 跨站脚本漏洞 4.8 -2018-12-03

All 17 known CVE vulnerabilities affecting Arigato Autoresponder and Newsletter with full Chinese analysis, references, and POCs where available.