Open Newsletter is a newsletter application with a modestly scoped vulnerability footprint that centers on its core product and reflects exposure to web-application-layer input-handling issues, particularly cross-site scripting. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Open Newsletter over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6785HIGH The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized | Dec 28, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-6786MEDIUM Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) | Dec 28, 2006 | 6.5 | 26 | NO | YES |
CVE-2007-6301MEDIUM Cross-site scripting (XSS) vulnerability in compose.php in OpenNewsletter 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter. | Dec 10, 2007 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Open Newsletter.
Media articles that mention a CVE ID that affects a product developed by Open Newsletter — matched by CVE ID, not by vendor name.