Extension WordPress
Vulnérabilités HubSpot All-In-One Marketing – Forms, Popups, Live Chat
Cette page rassemble les failles publiées pour HubSpot All-In-One Marketing – Forms, Popups, Live Chat, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de HubSpot All-In-One Marketing – Forms, Popups, Live Chat
5 fiches
HubSpot All-In-One Marketing <= 11.3.62 – Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script
The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. This makes it possible for…
*-11.3.62
11.3.64
16/07/2026
HubSpot All-In-One Marketing – Forms, Popups, Live Chat <= 11.3.56 – Authenticated (Contributor+) Information Exposure
The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.56. This makes it possible for authenticated attackers, with Contributor-level access and above,…
*-11.3.56
Non indiqué
01/07/2026
HubSpot All-In-One Marketing – Forms, Popups, Live Chat <= 11.3.32 – Missing Authorization to Authenticated (Contributor+) Installed Plugin Disclosure
The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.32 via the leadin/public/admin/class-adminconstants.php file. This makes it possible for authenticated attackers, with…
*-11.3.32
11.3.33
23/04/2026
HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics <= 11.1.22 – Authenticated (Contributor+) Stored Cross-Site Scripting via HubSpot Meeting Widget
The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute of the HubSpot Meeting Widget in all versions up to, and including, 11.1.22 due…
*-11.1.22
11.1.34
29/08/2024
HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics <= 8.8.13 – Server Side Request Forgery
The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could allow users with the edit_posts capability (by default contributor and above) to perform SSRF attacks
[*, 8.8.15)
8.8.15
11/04/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.