Activecampaign develops customer relationship management and marketing automation platforms that operate across email campaign, knowledge management, and support ticketing functions, making them widely embedded in business communication workflows. The vendor's vulnerability profile clusters around web-application and input-handling weaknesses—including cross-site scripting, SQL injection, cross-site request forgery, and authorization bypass—that are typical of platforms integrating user-generated content and multi-tenant data isolation, and the exposure shows a tendency to acquire public exploit code. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Activecampaign over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5919HIGH PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a | Nov 15, 2006 | 7.5 | 29 | NO | YES |
CVE-2003-1131HIGH PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page | Dec 31, 2003 | 7.5 | 29 | NO | YES |
CVE-2005-3679HIGH SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the | Nov 18, 2005 | 7.5 | 28 | NO | YES |
CVE-2024-32430CRITICAL Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8.1.14. | Apr 15, 2024 | 9.8 | 25 | NO | NO |
CVE-2006-1487MEDIUM Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the Knowl | Mar 29, 2006 | 4.3 | 21 | NO | YES |
CVE-2005-4634HIGH SQL injection vulnerability in index.php in ActiveCampaign SupportTrio 1.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the provenance o | Dec 31, 2005 | 7.5 | 21 | NO | NO |
CVE-2005-3829HIGH index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an invalid category parameter, which causes | Nov 26, 2005 | 7.8 | 20 | NO | NO |
CVE-2008-5055HIGH SQL injection vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to execute arbitrary SQL commands via the department_ | Nov 13, 2008 | 7.5 | 19 | NO | NO |
CVE-2006-0970HIGH PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files vi | Mar 3, 2006 | 7.5 | 19 | NO | NO |
CVE-2005-3828HIGH SQL injection vulnerability in index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the article parameter. | Nov 26, 2005 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Activecampaign.
Media articles that mention a CVE ID that affects a product developed by Activecampaign — matched by CVE ID, not by vendor name.