Aweber is an email marketing and automation platform with a focused vulnerability footprint centered on its web application layer. The durable signal points to authentication and input-handling issues, with recurring weaknesses in cross-site request forgery, cross-site scripting, and missing authorization checks that are characteristic of SaaS platforms managing user data and campaign workflows. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aweber over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47757HIGH Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in AWeber AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter | Nov 17, 2023 | 8.8 | 25 | NO | NO |
CVE-2024-13313MEDIUM The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scr | May 15, 2025 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aweber.
Media articles that mention a CVE ID that affects a product developed by Aweber — matched by CVE ID, not by vendor name.