All 36 CVE vulnerabilities found in Newsletters, with AI-generated Chinese analysis, references, and POCs.
This page aggregates vulnerability data for the product Newsletters, mapping specific security weaknesses to the relevant vendor and product categories. The collection encompasses a wide range of defect types, including buffer overflows, input validation errors, and privilege escalation issues, covering advisory records from 2005 through the present day. Readers can use this resource to track a vendor’s published security advisories, understand the impact of a particular weakness class, and review the complete vulnerability history associated with this product line. The interface allows filtering by weakness type, severity, and disclosure date, enabling precise analysis of historical and current security risks.
Vendor: Tribulant
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-37227 | WordPress Newsletters plugin <= 4.9.7 - Cross Site Request Forgery (CSRF) vulnerability | 4.3 | Medium | 2024-06-21 |
| CVE-2024-35718 | WordPress Newsletters plugin <= 4.9.5 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 | 7.1 | High | 2024-06-08 |
| CVE-2024-32954 | WordPress Newsletters plugin <= 4.9.5 - Arbitrary File Upload vulnerability CWE-434 | 9.1 | Critical | 2024-04-24 |
| CVE-2024-32953 | WordPress Newsletters plugin <= 4.9.5 - Sensitive Data Exposure vulnerability CWE-532 | 7.5 | High | 2024-04-24 |
| CVE-2023-4797 | Newsletter Lite < 4.9.3 - Admin+ Command Injection | 7.2 | - | 2024-01-16 |
| CVE-2023-30478 | WordPress Newsletters Plugin <= 4.8.8 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 | 5.4 | Medium | 2023-11-10 |
All 36 known CVE vulnerabilities affecting Newsletters with full Chinese analysis, references, and POCs where available.