PatchSiren

icegram CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM icegram CVE published 2026-08-01

CVE-2026-16087

The Icegram Engage plugin for WordPress has a second-order SQL injection vulnerability via the 'messages[][id]' parameter in versions up to and including 3.1.42. This allows authenticated attackers with contributor-level access to inject malicious SQL queries. The vulnerability arises from insufficient escaping of user-supplied parameters and lack of preparation on existing SQL queries. The attack involve [truncated]

MEDIUM icegram CVE published 2026-08-01

CVE-2026-15951

The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and including, 1.0.12. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the Icegram_Mailer_Logs_Table::get_logs() function. The vulnerability allows authenticated attackers with Administrator-level access to [truncated]