activecampaign CVE Vulnerabilities & Metrics

Focus on activecampaign vulnerabilities and metrics.

Last updated: 14 Apr 2025, 22:25 UTC

About activecampaign Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with activecampaign. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total activecampaign CVEs: 4
Earliest CVE date: 31 Dec 2003, 05:00 UTC
Latest CVE date: 15 Apr 2024, 08:15 UTC

Latest CVE reference: CVE-2024-32430

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical activecampaign CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.29

Max CVSS: 7.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 5
7.0-8.9 8
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS activecampaign CVEs

These are the five CVEs with the highest CVSS scores for activecampaign, sorted by severity first and recency.

All CVEs for activecampaign

CVE-2024-32430 activecampaign vulnerability CVSS: 0 15 Apr 2024, 08:15 UTC

Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8.1.14.

CVE-2023-0233 activecampaign vulnerability CVSS: 0 15 May 2023, 13:15 UTC

The ActiveCampaign WordPress plugin before 8.1.12 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-3923 activecampaign vulnerability CVSS: 0 09 Jan 2023, 23:15 UTC

The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs.

CVE-2021-24133 activecampaign vulnerability CVSS: 4.3 18 Mar 2021, 15:15 UTC

Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could allow attacker to make a logged-in administrator change API Credentials to attacker's account.

CVE-2008-5056 activecampaign vulnerability CVSS: 4.3 13 Nov 2008, 11:30 UTC

Cross-site scripting (XSS) vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to inject arbitrary web script or HTML via the department_id parameter to index.php.

CVE-2008-5055 activecampaign vulnerability CVSS: 7.5 13 Nov 2008, 11:30 UTC

SQL injection vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to execute arbitrary SQL commands via the department_id parameter to index.php.

CVE-2007-2630 activecampaign vulnerability CVSS: 6.5 11 May 2007, 17:19 UTC

Incomplete blacklist vulnerability in filemanager/browser/default/connectors/php/config.php in the FCKeditor module, as used in ActiveCampaign 1-2-All (aka 12All) 4.50 through 4.53.13, and possibly other products, allows remote authenticated administrators to upload and possibly execute .php4 and .php5 files via unspecified vectors. NOTE: this issue is reachable through filemanager/browser/default/browser.html.

CVE-2006-5919 activecampaign vulnerability CVSS: 7.5 15 Nov 2006, 15:07 UTC

PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the visEdit_root parameter, a different vector than CVE-2003-1131.

CVE-2006-1488 activecampaign vulnerability CVSS: 5.0 29 Mar 2006, 02:02 UTC

ActiveCampaign SupportTrio 2.5 allows remote attackers to obtain the full path of the server via invalid (1) article or (2) print parameters in a kb action to index.php, or (3) an invalid category parameter to modules/KB/pdf.php, which leaks the path in an error message.

CVE-2006-1487 activecampaign vulnerability CVSS: 4.3 29 Mar 2006, 02:02 UTC

Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the KnowledgeBase search module.

CVE-2006-0970 activecampaign vulnerability CVSS: 7.5 03 Mar 2006, 11:02 UTC

PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.

CVE-2005-4634 activecampaign vulnerability CVSS: 7.5 31 Dec 2005, 05:00 UTC

SQL injection vulnerability in index.php in ActiveCampaign SupportTrio 1.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the provenance of this information is unknown because the source URL is not available; the details are obtained solely from third party information.

CVE-2005-3829 activecampaign vulnerability CVSS: 7.8 26 Nov 2005, 19:03 UTC

index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an invalid category parameter, which causes a large number of SQL queries to be processed.

CVE-2005-3828 activecampaign vulnerability CVSS: 7.5 26 Nov 2005, 19:03 UTC

SQL injection vulnerability in index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the article parameter.

CVE-2005-3679 activecampaign vulnerability CVSS: 7.5 18 Nov 2005, 23:03 UTC

SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username field in the admin control panel.

CVE-2003-1131 activecampaign vulnerability CVSS: 7.5 31 Dec 2003, 05:00 UTC

PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code.