activecampaign
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting activecampaign.
- CVE-2025-32136WordPress ActiveCampaign Plugin <= 8.1.16 - Cross Site Scripting (XSS) vulnerability5.9
- CVE-2024-32430WordPress ActiveCampaign plugin <= 8.1.14 - Server Side Request Forgery (SSRF) vulnerability4.4
- CVE-2023-0233ActiveCampaign < 8.1.12 - Contributor+ Stored XSS5.4
- CVE-2022-3923ActiveCampaign for WooCommerce < 1.9.8 - Subscriber+ Error Log Cleanup4.3
- CVE-2021-24133ActiveCampaign < 8.0.2 - Cross-Site Request Forgery in Settings4.3
- CVE-2008-5056Cross-site scripting (XSS) vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to inject arbitrary web script or HTML via the department...4.3
- CVE-2008-5055SQL injection vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to execute arbitrary SQL commands via the department_id parameter to i...7.5
- CVE-2007-2630Incomplete blacklist vulnerability in filemanager/browser/default/connectors/php/config.php in the FCKeditor module, as used in ActiveCampaign 1-2-All (aka 12All) 4.50 through 4.53.13, and possibly...6.5
- CVE-2006-5919PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the visEd...7.5
- CVE-2006-1488ActiveCampaign SupportTrio 2.5 allows remote attackers to obtain the full path of the server via invalid (1) article or (2) print parameters in a kb action to index.php, or (3) an invalid category ...5.0
- CVE-2006-1487Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the KnowledgeBase search m...4.3
- CVE-2006-0970PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parame...7.5
- CVE-2005-4634SQL injection vulnerability in index.php in ActiveCampaign SupportTrio 1.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the provenance of this informatio...7.5
- CVE-2005-3829index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an invalid category parameter, which causes a large number of...7.8
- CVE-2005-3828SQL injection vulnerability in index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the article parameter.7.5