Interspire develops a narrow product line centered on email marketing and knowledge management software, with a modest but recurring vulnerability footprint that achieves prominence disproportionate to its CVE volume through persistent public exploit availability. The exposure recurs across products such as Email Marketer, ActiveKB, and ArticleLive and their newer NX variants, clustering around web application input-handling weaknesses including SQL injection, cross-site scripting, path traversal, and improper authentication mechanisms. These weakness classes are characteristic of legacy web applications and reflect insufficient input sanitization and access control, both common targets for tooling and exploitation frameworks. Defenders operating these platforms should treat available exploit code as an immediate patching trigger and prioritize network segmentation and access controls around the email and knowledge-management tiers; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Interspire over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14322CRITICAL The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attackers to bypass authentication an | Oct 18, 2017 | 9.8 | 62 | NO | YES |
CVE-2018-19550HIGH Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessi | Nov 26, 2018 | 8.8 | 40 | NO | YES |
CVE-2009-4957HIGH Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary files and possibly have unspecified other impact via directory t | Jul 22, 2010 | 7.5 | 33 | NO | YES |
CVE-2007-1060MEDIUM Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled, allow remote attackers to exe | Feb 22, 2007 | 6.8 | 31 | NO | YES |
CVE-2008-2338HIGH Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts in /admin. | May 19, 2008 | 7.5 | 30 | NO | YES |
CVE-2022-40777HIGH Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessi | Oct 11, 2022 | 8.8 | 28 | NO | NO |
CVE-2007-5131HIGH SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the catId parameter in a browse action. NOTE: | Sep 27, 2007 | 7.5 | 28 | NO | YES |
CVE-2018-19553HIGH Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php | Nov 26, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-19552HIGH Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php. | Nov 26, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-19551HIGH Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php. | Nov 26, 2018 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Interspire.
Media articles that mention a CVE ID that affects a product developed by Interspire — matched by CVE ID, not by vendor name.