Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Activecampaign

First CVE: Dec 31, 2003Active for: 23 yearsTotal CVEs: 18
33.0
VTI Score
Medium

Activecampaign develops customer relationship management and marketing automation platforms that operate across email campaign, knowledge management, and support ticketing functions, making them widely embedded in business communication workflows. The vendor's vulnerability profile clusters around web-application and input-handling weaknesses—including cross-site scripting, SQL injection, cross-site request forgery, and authorization bypass—that are typical of platforms integrating user-generated content and multi-tenant data isolation, and the exposure shows a tendency to acquire public exploit code. Current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Activecampaign over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2003
22 years ago
Most Recent CVE
Apr 4, 2025
476 days ago

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-5919HIGH
PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a
Nov 15, 20067.529NOYES
CVE-2003-1131HIGH
PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page
Dec 31, 20037.529NOYES
CVE-2005-3679HIGH
SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the
Nov 18, 20057.528NOYES
CVE-2024-32430CRITICAL
Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8.1.14.
Apr 15, 20249.825NONO
CVE-2006-1487MEDIUM
Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the Knowl
Mar 29, 20064.321NOYES
CVE-2005-4634HIGH
SQL injection vulnerability in index.php in ActiveCampaign SupportTrio 1.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the provenance o
Dec 31, 20057.521NONO
CVE-2005-3829HIGH
index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an invalid category parameter, which causes
Nov 26, 20057.820NONO
CVE-2008-5055HIGH
SQL injection vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to execute arbitrary SQL commands via the department_
Nov 13, 20087.519NONO
CVE-2006-0970HIGH
PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files vi
Mar 3, 20067.519NONO
CVE-2005-3828HIGH
SQL injection vulnerability in index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the article parameter.
Nov 26, 20057.519NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
50%
44%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (27.8%)
Unknown13 (72.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (27.8%)
High0 (0.0%)
Unknown13 (72.2%)
User Interaction
None2 (11.1%)
Unknown13 (72.2%)
Required3 (16.7%)
Privileges Required
Low2 (11.1%)
High1 (5.6%)
None2 (11.1%)
Unknown13 (72.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
22.2% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Activecampaign.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Activecampaign — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Activecampaign's Products

View all 3 CNAs →

Top CWEs