Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Icegram

First CVE: Jan 26, 2018Active for: 8 yearsTotal CVEs: 48
35.0
VTI Score
Medium

Icegram develops a focused suite of email marketing and customer engagement products, including its flagship Email Subscribers & Newsletters, Engage, Express, and Collect platforms, which serve as plugins and hosted solutions for building and managing customer communications. Despite its narrow product portfolio, the vendor ranks among the more prominent vulnerability disclosures in the landscape, driven by vulnerabilities that skew toward serious outcomes and a moderate tendency toward public exploit availability. The recurring weakness classes—cross-site scripting, SQL injection, CSRF, missing authorization, and exposure of sensitive information—reflect the web-application and database-interaction surface typical of email-marketing and form-collection software, where improper input handling and access control directly expose customer data and platform integrity. Defenders should prioritize patches for Icegram deployments given the elevation in critical-severity findings and the email subscriber databases these products typically access; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
48
Total CVEs
More Total CVEs than 98% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Icegram over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2018
8 years ago
Most Recent CVE
Nov 21, 2025
245 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (48 CVEs).

48 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-20361CRITICAL
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL
Jan 8, 20209.888NOYES
CVE-2019-19985MEDIUM
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
Dec 26, 20195.376NOYES
CVE-2024-4295CRITICAL
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficie
Jun 5, 20249.846NOYES
CVE-2022-0439HIGH
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it v
Mar 7, 20228.841NOYES
CVE-2019-13569CRITICAL
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a
Jul 19, 20199.831NONO
CVE-2024-5756CRITICAL
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via t
Jun 21, 20249.830NONO
CVE-2024-6172CRITICAL
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via t
Jul 2, 20249.829NONO
CVE-2022-45810CRITICAL
Improper Neutralization of Formula Elements in a CSV File vulnerability in Icegram Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce.This is
Nov 7, 20239.828NONO
CVE-2022-3981HIGH
The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by an
Dec 12, 20228.827NONO
CVE-2024-37252CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affect
Jun 26, 20249.326NONO
View all 48 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products48 CVEs
65%
17%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network48 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low48 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None25 (52.1%)
Unknown0 (0.0%)
Required23 (47.9%)
Privileges Required
Low13 (27.1%)
High12 (25.0%)
None23 (47.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (48 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.1% of CVEs· 97th percentile
Nuclei
3 CVEs
6.2% of CVEs· 96th percentile
ExploitDB
2 CVEs
4.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Icegram.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Icegram — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Icegram's Products

View all 5 CNAs →

Top CWEs