Mailpoet
This hub aggregates every CVE we track for Mailpoet, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM3HIGH1
Monthly trend
0
0
1
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
2024-092026-08
Latest CVEs
The 4 most recently published vulnerabilities affecting Mailpoet.
- CVE-2026-57626WordPress MailPoet plugin 5.30.0-5.33.0 - Cross Site Request Forgery (CSRF) vulnerability7.1
- CVE-2024-12743MailPoet < 5.5.2 - Admin+ Stored XSS4.8
- CVE-2024-10103MailPoet < 5.3.2 - Admin+ Stored XSS6.1
- CVE-2019-11843The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).6.1
Product normalization is registry-driven with AI assist and human review. How it works