ConvertKit records
4 published records for vendor convertkit.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2024-31245No exploit | WordPress ConvertKit plugin <= 2.4.5 - Email Disclosure in Log File vulnerabilityconvertkit · convertkit - email marketing\, email newsletter and landing pages · CWE-532 | High7.5 | — | 0.5% | Apr 10, 2024 |
24Monitor | CVE-2023-2337No exploit | ConvertKit < 2.2.1 - Reflected XSSconvertkit · convertkit - email marketing\, email newsletter and landing pages · CWE-79 | Medium6.1 | — | 0.5% | Jun 5, 2023 |
21Monitor | CVE-2022-4508No exploit | ConvertKit < 2.0.5 - Contributor+ Stored XSSconvertkit · convertkit - email marketing\, email newsletter and landing pages · CWE-79 | Medium5.4 | — | 0.5% | Jan 16, 2023 |
21Monitor | CVE-2024-3961No exploit | ConvertKit <= 2.4.9 - Missing Authorizationconvertkit · convertkit - email marketing\, email newsletter and landing pages · CWE-862 | Medium5.3 | — | 0.4% | Jun 21, 2024 |
- CVE-2024-3124530Monitor
WordPress ConvertKit plugin <= 2.4.5 - Email Disclosure in Log File vulnerability
HighCVSS 7.5No exploitEPSS 1%convertkit · convertkit - email marketing\, email newsletter and landing pagesApr 10, 2024
- CVE-2023-233724Monitor
ConvertKit < 2.2.1 - Reflected XSS
MediumCVSS 6.1No exploitEPSS 0%convertkit · convertkit - email marketing\, email newsletter and landing pagesJun 5, 2023
- CVE-2022-450821Monitor
ConvertKit < 2.0.5 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%convertkit · convertkit - email marketing\, email newsletter and landing pagesJan 16, 2023
- CVE-2024-396121Monitor
ConvertKit <= 2.4.9 - Missing Authorization
MediumCVSS 5.3No exploitEPSS 0%convertkit · convertkit - email marketing\, email newsletter and landing pagesJun 21, 2024