Mailpoet

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-57626

    WordPress MailPoet plugin 5.30.0-5.33.0 - Cross Site Request Forgery (CSRF) vulnerability

    Last Modified: Jul 23, 2026
    Published: Jul 23, 2026

    CVE-2024-10103

    MailPoet < 5.3.2 - Admin+ Stored XSS

    Last Modified: Jun 12, 2025
    Published: Nov 19, 2024

    CVE-2018-20853

    An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks.

    Last Modified: Nov 21, 2024
    Published: Nov 06, 2019

    CVE-2014-3907

    Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote attackers to hijack the authentication of arbitrary users.

    Last Modified: Apr 12, 2025
    Published: Aug 26, 2014

    CVE-2014-4725

    The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

    Last Modified: Apr 12, 2025
    Published: Jul 27, 2014
    Items Per Page
    Mailpoet Vulnerabilities & Security CVEs | CVE-DB