Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Tribulant Software — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting Tribulant Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Tribulant Software develops e-commerce and content management solutions, with 10 CVEs recorded primarily involving remote code execution, cross-site scripting, and privilege escalation vulnerabilities. Historically, their products have shown weaknesses in input validation and access control, allowing attackers to execute unauthorized commands or compromise user accounts. While no major public security incidents have been documented, the consistent pattern of vulnerabilities suggests potential risks for organizations using their platforms without proper hardening. Security researchers have identified multiple flaws that could lead to complete system compromise if exploited, emphasizing the need for regular patching and security assessments for deployments of their software.

CVE ID Title CVSS Severity Published
CVE-2026-66619 WordPress Newsletters plugin <= 4.18 - SQL Injection vulnerability — Newsletters CWE-89 7.6 High 2026-09-17
CVE-2026-57394 WordPress Newsletters plugin <= 4.14 - Cross Site Scripting (XSS) vulnerability — Newsletters CWE-79 7.1 High 2026-07-13
CVE-2026-57645 WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability — Newsletters CWE-862 8.1 High 2026-06-26
CVE-2026-54840 WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability — Newsletters CWE-862 7.3 High 2026-06-26
CVE-2025-67911 WordPress Newsletters plugin <= 4.11 - PHP Object Injection vulnerability — Newsletters CWE-502 9.8 Critical 2026-01-08
CVE-2025-69020 WordPress Newsletters plugin <= 4.12 - Cross Site Scripting (XSS) vulnerability — Newsletters CWE-79 6.5 Medium 2025-12-30
CVE-2025-54034 WordPress Newsletters plugin <= 4.10 - Local File Inclusion vulnerability — Newsletters CWE-98 7.5 High 2025-08-20
CVE-2025-54035 WordPress Newsletters plugin <= 4.10 - Cross Site Request Forgery (CSRF) Vulnerability — Newsletters CWE-352 4.3 Medium 2025-07-16
CVE-2025-30858 WordPress Snow Storm plugin <= 1.4.6 - Reflected Cross Site Scripting (XSS) vulnerability — Snow Storm CWE-79 7.1 High 2025-04-03
CVE-2025-30921 WordPress Newsletters plugin <= 4.9.9.7 - SQL Injection vulnerability — Newsletters CWE-89 7.6 High 2025-03-27
CVE-2025-26931 WordPress Tribulant Gallery Voting plugin <= 1.2.1 - CSRF to Stored XSS vulnerability — Tribulant Gallery Voting CWE-352 7.1 High 2025-02-25
CVE-2025-24599 WordPress Newsletters plugin <= 4.9.9.6 - Reflected Cross Site Scripting (XSS) vulnerability — Newsletters CWE-79 7.1 High 2025-02-04
CVE-2024-47346 WordPress Newsletters plugin <= 4.9.9.1 - Reflected Cross Site Scripting (XSS) vulnerability — Newsletters CWE-79 7.1 High 2024-10-06
CVE-2024-47376 WordPress Slideshow Gallery LITE plugin <= 1.8.3 - Cross Site Scripting (XSS) vulnerability — Slideshow Gallery CWE-79 5.9 Medium 2024-10-05

This page lists every published CVE security advisory associated with Tribulant Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.