Extension WordPress

Vulnérabilités Brevo – Email, SMS, Web Push, Chat, and more.

Cette page rassemble les failles publiées pour Brevo – Email, SMS, Web Push, Chat, and more., leurs plages de versions affectées et les correctifs signalés dans la base locale.

9Vulnérabilités
0Critiques
9Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Brevo – Email, SMS, Web Push, Chat, and more.

9 fiches

CVE-2025-14799 Moyenne · 6,5
Brevo – Email, SMS, Web Push, Chat, and more.

Brevo – Email, SMS, Web Push, Chat, and more. <= 3.3.0 – Unauthenticated Authorization Bypass via Type Juggling

The Brevo – Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type juggling in all versions up to, and including, 3.3.0. This is due to the use of loose…

Versions affectées

*-3.3.0

Correctif

3.3.1

Publication

17/02/2026

CVE-2024-8477 Moyenne · 4,3
Brevo – Email, SMS, Web Push, Chat, and more.

Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.87 – Cross-Site Request Forgery

The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.87. This is due to missing or incorrect nonce validation…

Versions affectées

*-3.1.87

Correctif

3.1.88

Publication

09/10/2024

CVE-2024-43287 Moyenne · 4,3
Brevo – Email, SMS, Web Push, Chat, and more.

Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.82 – Cross-Site Request Forgery

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.82. This is due to missing or incorrect nonce validation on the process_bulk_action()…

Versions affectées

*-3.1.82

Correctif

3.1.83

Publication

16/08/2024

CVE-2024-35668 Moyenne · 6,1
Brevo – Email, SMS, Web Push, Chat, and more.

Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.77 – Reflected Cross-Site Scripting

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-3.1.77

Correctif

3.1.78

Publication

03/06/2024

CVE-2026-15297 Moyenne · 6,1
Brevo – Email, SMS, Web Push, Chat, and more.

Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.77 – Reflected Cross-Site Scripting

The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization…

Versions affectées

*-3.1.77

Correctif

3.1.78

Publication

22/03/2024

CVE-2023-2472 Moyenne · 6,1
Brevo – Email, SMS, Web Push, Chat, and more.

Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.60 – Reflected Cross-Site Scripting via 'lang'

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in versions up to, and including, 3.1.60 due to insufficient input sanitization and output escaping.…

Versions affectées

*-3.1.60

Correctif

3.1.61

Publication

10/05/2023

CVE-2021-24874 Moyenne · 6,1
Brevo – Email, SMS, Web Push, Chat, and more.

Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.30 – Reflected Cross-Site Scripting via lang & pid Parameters

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

Versions affectées

[*, 3.1.31)

Correctif

3.1.31

Publication

12/01/2022

CVE-2021-24923 Moyenne · 6,1
Brevo – Email, SMS, Web Push, Chat, and more.

Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.24 – Reflected Cross-Site Scripting

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

Versions affectées

[*, 3.1.25)

Correctif

3.1.25

Publication

23/12/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités