Icegram develops a focused suite of email marketing and customer engagement products, including its flagship Email Subscribers & Newsletters, Engage, Express, and Collect platforms, which serve as plugins and hosted solutions for building and managing customer communications. Despite its narrow product portfolio, the vendor ranks among the more prominent vulnerability disclosures in the landscape, driven by vulnerabilities that skew toward serious outcomes and a moderate tendency toward public exploit availability. The recurring weakness classes—cross-site scripting, SQL injection, CSRF, missing authorization, and exposure of sensitive information—reflect the web-application and database-interaction surface typical of email-marketing and form-collection software, where improper input handling and access control directly expose customer data and platform integrity. Defenders should prioritize patches for Icegram deployments given the elevation in critical-severity findings and the email subscriber databases these products typically access; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Icegram over time
Signals from CVEs in this vendor scope (48 CVEs).
48 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-20361CRITICAL There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL | Jan 8, 2020 | 9.8 | 88 | NO | YES |
CVE-2019-19985MEDIUM The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure. | Dec 26, 2019 | 5.3 | 76 | NO | YES |
CVE-2024-4295CRITICAL The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficie | Jun 5, 2024 | 9.8 | 46 | NO | YES |
CVE-2022-0439HIGH The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it v | Mar 7, 2022 | 8.8 | 41 | NO | YES |
CVE-2019-13569CRITICAL A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a | Jul 19, 2019 | 9.8 | 31 | NO | NO |
CVE-2024-5756CRITICAL The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via t | Jun 21, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-6172CRITICAL The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via t | Jul 2, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-45810CRITICAL Improper Neutralization of Formula Elements in a CSV File vulnerability in Icegram Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce.This is | Nov 7, 2023 | 9.8 | 28 | NO | NO |
CVE-2022-3981HIGH The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by an | Dec 12, 2022 | 8.8 | 27 | NO | NO |
CVE-2024-37252CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affect | Jun 26, 2024 | 9.3 | 26 | NO | NO |
Signals from CVEs in this vendor scope (48 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Icegram.
Media articles that mention a CVE ID that affects a product developed by Icegram — matched by CVE ID, not by vendor name.