Vulnerabilities (CVE)

Filtered by vendor Kibokolabs Subscribe
Total 63 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1002001 1 Kibokolabs 1 Arigato Autoresponder And Newsletter 2018-12-27 3.5 LOW 4.8 MEDIUM
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
CVE-2018-1002009 1 Kibokolabs 1 Arigato Autoresponder And Newsletter 2018-12-27 3.5 LOW 4.8 MEDIUM
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in unsubscribe.html.php:3: via GET reuqest to the email variable.
CVE-2018-18461 1 Kibokolabs 1 Arigato Autoresponder And Newsletter 2018-11-30 7.5 HIGH 9.8 CRITICAL
The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php.