Where
-Infinity
0

Icegram Icegram Engage – Popups, Optins, CTAs & Lead GenerationIcegram Engage <= 3.1.42 - Authenticated (Contributor+) Second-Order SQL Injection via 'messages[][id]' Parameter

Risk 38
Severity
6.5
First published (updated )

Icegram Icegram Express ProWordPress Icegram Express Pro plugin < 5.9.14 - PHP Object Injection vulnerability

Risk 66
Severity
7.2
First published (updated )

Icegram Email Subscribers & NewslettersWordPress Email Subscribers & Newsletters plugin <= 5.9.10 - PHP Object Injection vulnerability

Risk 66
Severity
7.2
First published (updated )

Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPressEmail Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Mailing Queue Trigger

Risk 27
Severity
5.3
First published (updated )

Icegram Icegram Express ProWordPress Icegram Express Pro plugin <= 5.9.5 - Server Side Request Forgery (SSRF) vulnerability

Risk 28
Severity
4.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Icegram EngageIcegram Engage < 3.1.32 - Admin+ Stored XSS

Risk 29
Severity
4.8
First published (updated )

Icegram EngageIcegram Engage < 3.1.32 - Admin+ Stored XSS

Risk 29
Severity
4.8
First published (updated )

Icegram ExpressEmail Subscribers < 5.7.50 - Admin+ Stored XSS in Template

Risk 38
Severity
6.1
First published (updated )

Icegram Email SubscribersEmail Subscribers < 5.7.52 - Admin+ Stored XSS

Risk 24
Severity
3.5
First published (updated )

Icegram Icegram (WordPress plugin)WordPress Icegram Engage plugin <= 3.1.31 - Cross Site Scripting (XSS) vulnerability

Risk 26
Severity
6.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Icegram Email SubscribersEmail Subscribers < 5.7.45 - Admin+ Stored XSS

Risk 29
Severity
4.8
First published (updated )

Icegram Email SubscribersEmail Subscribers < 5.7.45 - Admin+ Stored XSS

Risk 29
Severity
4.8
First published (updated )

Icegram Email SubscribersEmail Subscribers < 5.7.45 - Admin+ Stored XSS

Risk 29
Severity
4.8
First published (updated )

Icegram Email Subscribers \& Newsletters WordpressEmail Subscribers < 5.7.45 - Admin+ Stored XSS

Risk 29
Severity
4.8
First published (updated )

Icegram Email SubscribersEmail Subscribers < 5.7.44 - Admin+ SQL Injection

Risk 49
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Icegram EngageIcegram Engage < 3.1.32 - Author+ Stored XSS

Risk 38
Severity
6.1
First published (updated )

Icegram IcegramWordPress Icegram Engage plugin <= 3.1.24 - Unauthenticated Message Duplication Vulnerability

Risk 27
Severity
5.3
First published (updated )

Icegram Icegram CollectWordPress Icegram Collect plugin <= 1.3.14 - Broken Access Control vulnerability

Risk 34
Severity
5.4
First published (updated )

Icegram Email Subscribers \& Newsletters WordpressEmail Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Authenticated (Subscriber+) Arbitrary Shortcode Execution

Risk 33
Severity
6.3
EPSS
0.05%
First published (updated )

Icegram Email Subscribers by Icegram ExpressEmail Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure

Risk 16
Severity
4.3
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Icegram IcegramWordPress Icegram Engage plugin <= 3.1.24 - Unauthenticated Unpublished Campaign Viewer vulnerability

Risk 27
Severity
5.3
First published (updated )

Icegram IcegramWordPress Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA plugin <= 3.1.25 - Cross Site Scripting (XSS) vulnerability

Risk 46
Severity
6.5
First published (updated )

Icegram Email Subscribers \& Newsletters WordpressIcegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.26 - Missing Authorization

Risk 16
Severity
4.3
EPSS
0.05%
First published (updated )

Icegram Email Subscribers \& Newsletters WordpressEmail Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.25 - Unauthenticated SQL Injection via unsubscribe

Risk 61
Severity
9.8
EPSS
0.06%
First published (updated )

Icegram Email Subscribers & NewslettersWordPress Email Subscribers by Icegram Express plugin <= 5.7.25 - SQL Injection vulnerability

Risk 61
Severity
9.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Icegram Icegram Express WordpressIcegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.23 - Unauthenticated SQL Injection via optin

Risk 61
Severity
9.8
EPSS
0.06%
First published (updated )

Icegram Icegram Express WordpressIcegram Express <= 5.7.22 - Authenticated (Subscriber+) SQL Injection Vulnerability via options[list_id]

Risk 56
Severity
8.8
EPSS
0.05%
First published (updated )

Icegram Email Subscribers \& Newsletters WordpressWordPress Icegram Express plugin <= 5.7.13 - Broken Access Control vulnerability

Risk 86
Severity
9.8
First published (updated )

Icegram Icegram Express WordpressWordPress Icegram Engage plugin <= 3.1.21 - Broken Access Control vulnerability

Risk 34
Severity
5.4
First published (updated )

Icegram Email Subscribers \& Newsletters WordpressEmail Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash

Risk 61
Severity
9.8
EPSS
0.09%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203