Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 20 Jan 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 20 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Zoho Mail Zoho Mail zoho Zeptomail |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Zoho Mail Zoho Mail zoho Zeptomail |
Wed, 31 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 31 Dec 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail Zoho ZeptoMail allows Stored XSS.This issue affects Zoho ZeptoMail: from n/a through 3.3.1. | |
| Title | WordPress Zoho ZeptoMail plugin <= 3.3.1 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-01-20T14:28:06.018Z
Reserved: 2025-05-30T14:04:14.278Z
Link: CVE-2025-49028
Updated: 2025-12-31T15:23:11.448Z
Status : Awaiting Analysis
Published: 2025-12-31T09:15:50.830
Modified: 2026-01-20T15:16:31.343
Link: CVE-2025-49028
No data.
OpenCVE Enrichment
Updated: 2026-01-05T10:18:03Z