constantcontact CVE Vulnerabilities & CVE List (5)

Products (CPE): — CVEs: 5

constantcontact vulnerability overview

Aggregates CVE and security vulnerability intelligence across all constantcontact-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk csrf, vendor risk cross-site scripting, and vendor risk path handling; exposure may include vendor impact file overwrite in vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 15 of 5 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-52208 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Constant Contact Constant Contact Forms.This issue affects Constant Contact Forms: from n/a through 2.4.2. [email protected] 5.3 0.50% 2024-01-08 2026-04-28
CVE-2022-44740 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Creative Mail plugin <= 1.5.4 on WordPress. [email protected] 5.4 0.10% 2022-11-18 2024-11-21
CVE-2022-40687 Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress. [email protected] 5.4 1.49% 2022-11-18 2024-11-21
CVE-2022-40686 Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress. [email protected] 5.4 0.11% 2022-11-18 2024-11-21
CVE-2021-24134 Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript code or HTML in posts where the malicious form is embed. [email protected] 4.8 0.19% 2021-03-18 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence