Icegram has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 7.7 (high).
CVEs per month
Last 12 months, by publish date
1125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/091026/10
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.7
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Products
- Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress 1
- icegram 1
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-97284High· 8.8Contributor PHP Object Injection in Icegram <= 3.1.31 versions.48CVE-2026-12757Medium· 6.5The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.2736
Icegram vulnerabilities
CVEs affecting Icegram, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-97284High· 8.8Contributor PHP Object Injection in Icegram <= 3.1.31 versions.
Contributor PHP Object Injection in Icegram <= 3.1.31 versions.
▾ TwilightIcegram · icegramvia NVD
CVE-2026-12757Medium· 6.5The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27
The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due…
▾ Sunliticegram · Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPressEPSS 0.33%via NVD