Constantcontact operates email marketing and web-form automation platforms including Creative Mail and Constant Contact Forms, with a reported vulnerability footprint centered on web-application security concerns. The observed weakness classes—including cross-site request forgery, cross-site scripting, and exposure of sensitive information—reflect typical input-handling and session-management risks in customer-facing web services. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Constantcontact over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40687HIGH Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress. | Nov 18, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-40686HIGH Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress. | Nov 18, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-44740HIGH Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Creative Mail plugin <= 1.5.4 on WordPress. | Nov 18, 2022 | 8.8 | 27 | NO | NO |
CVE-2023-52208HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Constant Contact Constant Contact Forms.This issue affects Constant Contact Forms: from n/a through 2.4. | Jan 8, 2024 | 7.5 | 19 | NO | NO |
CVE-2021-24134MEDIUM Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, w | Mar 18, 2021 | 4.8 | 17 | NO | NO |
CVE-2023-34387MEDIUM Missing Authorization vulnerability in Constant Contact Constant Contact Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Constant C | Dec 13, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Constantcontact.
Media articles that mention a CVE ID that affects a product developed by Constantcontact — matched by CVE ID, not by vendor name.