CVE-2025-14799
Brevo – Email, SMS, Web Push, Chat, and more.
Minimum safe version
3.3.1
Update to 3.3.1 or later to address 12 fixable vulnerabilities
CVE-2024-8477
CVE-2024-43287
CVE-2024-35668
Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.77 - Reflected Cross-Site Scripting
WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue Plugin < 3.1.61 is vulnerable to Cross Site Scripting (XSS)
WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue Plugin <= 3.1.60 is vulnerable to Cross Site Scripting (XSS)
Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.60 - Reflected Cross-Site Scripting via 'lang'
Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.39 - Cross-Site Scripting
WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin <= 3.1.24 - Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2021-24923
CVE-2021-24874