| [Critical] Unauthorized Cross-Tenant Data Access in Stripo AI Hub Campaign via Deleted Project. |
Improper Access Control - Generic |
srcode |
Critical |
2026-01-20 |
| [my.stripo.email] Blind SSRF Vulnerability in Stripo App Export via Missing Endpoints Export Email Message to Zapier |
Server-Side Request Forgery (SSRF) |
odaysec |
Critical |
2025-12-01 |
| [SSRF] my.stripo.email via the setup-wizard parameter |
Server-Side Request Forgery (SSRF) |
deb0con |
Critical |
2024-02-15 |
| [demo.stripo.email] HTTP request Smuggling |
HTTP Request Smuggling |
deb0con |
Medium |
2024-02-15 |
| Non-revoked API Key Disclosure in a Disclosed API Key Disclosure Report on Stripo |
Cleartext Transmission of Sensitive Information |
sankalpa_1337 |
Medium |
2024-02-15 |
| Non-revoked API Key Information disclosure via Stripo_report() |
Cleartext Storage of Sensitive Information |
deb0con |
Medium |
2022-08-25 |
| Upload Profile Photo in any folder you want with any extension you want |
Privilege Escalation |
whoisbinit |
Critical |
2022-03-30 |
| Insecure Storage and Overly Permissive API Keys |
Missing Encryption of Sensitive Data |
dc61703fdbcd3f8331d3dc24078c01 |
Medium |
2022-03-30 |
| Ability to use premium templates as free user via https://stripo.email/templates/?utm_source=viewstripo&utm_medium=referral |
Business Logic Errors |
20kilograma |
High |
2022-03-30 |
| Bypassing Content-Security-Policy leads to open-redirect and iframe xss |
Open Redirect |
echidonut |
Medium |
2021-07-30 |
| Stored XSS at Module Name |
Cross-site Scripting (XSS) - Stored |
20kilograma |
Medium |
2021-04-12 |
| Stored XSS in the banner block description |
Cross-site Scripting (XSS) - Stored |
solov9ev |
Medium |
2021-03-09 |
| Memory Dump and Env Disclosure via Spring Boot Actuator |
Misconfiguration |
0xwise |
Medium |
2021-03-02 |
| Able to use 'PREMIUM TEMPLATES' in 'FREE PLAN' at [https://my.stripo.email/cabinet/#/my-templates/] |
Business Logic Errors |
xploiterr |
High |
2021-01-25 |
| Bypass of #1047119: Missing Rate Limit while creating Plug-Ins at https://my.stripo.email/cabinet/plugins/ |
Business Logic Errors |
savxiety |
Medium |
2021-01-13 |
| No rate limit in email subscription |
Business Logic Errors |
splint3rsec |
Medium |
2021-01-11 |
| No rate limiting - Create data |
Business Logic Errors |
ofjaaaah |
Medium |
2021-01-05 |
| No rate limiting - Create Plug-ins |
Business Logic Errors |
ofjaaaah |
Medium |
2021-01-05 |
| Stored XSS at "Conditions " through "My Custom Rule" Field at [https://my.stripo.email/cabinet/#/template-editor/] in Template Editor. |
Cross-site Scripting (XSS) - Stored |
xploiterr |
Medium |
2020-12-24 |
| Stored XSS at Template Editor in "Section Name" Field of Block element 'Accordion'. |
Cross-site Scripting (XSS) - Stored |
xploiterr |
Medium |
2020-12-24 |
| Permanent DOS for new users! |
Uncontrolled Resource Consumption |
akashhamal0x01 |
High |
2020-12-21 |
| No rate limiting for confirmation email lead to huge Mass mailings |
Business Logic Errors |
buggfuzz1 |
Medium |
2020-12-11 |
| SSRF external interaction |
Server-Side Request Forgery (SSRF) |
0xcharan |
Low |
2020-12-11 |
| Non-revoked API Key Disclosure in a Disclosed API Key Disclosure Report on Stripo |
Cleartext Storage of Sensitive Information |
whoisbinit |
Medium |
2020-12-04 |
| No rate limiting for subscribe email + lead to Cross origin misconfiguration |
Business Logic Errors |
kittytrace |
Medium |
2020-11-30 |
| Race condition on my.stripo.email at /cabinet/stripeapi/v1/projects/298427/emails/folders uri |
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') |
bminossi |
Medium |
2020-11-09 |
| weak password poilicy in signup password leak to account takeover |
Violation of Secure Design Principles |
assafkiller |
None |
2020-10-16 |
| SSL cookie without secure flag set |
None supplied |
classifled |
Medium |
2020-10-13 |
| Public and secret api key leaked in JavaScript source |
Cleartext Storage of Sensitive Information |
0x4_aulia |
Medium |
2020-09-29 |
| No CSRF Protection in Resend Confirmation Email feature leads to Sending Unwanted Email in Victim's Inbox without knowing Victim's email address |
Cross-Site Request Forgery (CSRF) |
binit |
Medium |
2020-09-08 |
| Cross-Site WebSocket Hijacking Lead to Steal XSRF-TOKEN |
Improper Access Control - Generic |
3x3s |
High |
2020-07-27 |
| Integer Overflow (CVE_2017_7529) |
Integer Overflow |
whitehatmat |
Medium |
2020-07-13 |
| SSRF via Export Service in ActiveCampaign |
Server-Side Request Forgery (SSRF) |
dotsecurity |
High |
2020-07-13 |
| [www.stripo.email] There is no rate limit for /it/contact-us/ endpoints |
Improper Authentication - Generic |
what_web |
Low |
2020-07-03 |
| multiple email usage -my.stripo.email- |
Improper Access Control - Generic |
mraldersonn |
Medium |
2020-07-03 |
| SSRF in my.stripo.email |
Server-Side Request Forgery (SSRF) |
x25s |
High |
2020-06-30 |
| [www.stripo.email] You can bypass the speed limit by changing the IP. |
Information Exposure Through Debug Information |
what_web |
Medium |
2020-06-30 |
| [www.stripo.email] There is no rate limit for contact-us endpoints |
Improper Authorization |
what_web |
Low |
2020-05-26 |
| CORS on my.stripo.email |
None supplied |
nihadp |
No rating |
2020-04-28 |
| [www.stripo.email] You can override the speed limit by adding the X-Forwarded-For header. |
Improper Authorization |
what_web |
Medium |
2020-04-23 |
| Unrestricted File Upload on https://my.stripo.email and https://stripo.email |
Unrestricted Upload of File with Dangerous Type |
doctor_spooky |
Medium |
2020-04-13 |
| SSRF in Export template to ActiveCampaign |
Server-Side Request Forgery (SSRF) |
c1kada |
Medium |
2020-04-10 |
| HTTP Request Smuggling on my.stripo.email |
None supplied |
codeslayer1337 |
High |
2020-04-10 |
| XSRF Token is Not being validated when sending emails test request which lead to CSRF attack using the flash file + 307 redirect technique |
Cross-Site Request Forgery (CSRF) |
pain45 |
Medium |
2020-03-25 |
| Strored Xss on https://my.stripo.email/ ( multiple inputs) |
Cross-site Scripting (XSS) - Stored |
pain45 |
Medium |
2020-03-25 |
| Blind SSRF while Creating Templates |
Server-Side Request Forgery (SSRF) |
dotsecurity |
High |
2020-03-24 |
| Email verification bypasa |
Incorrect Authorization |
d3ltaf0rc3 |
High |
2020-03-24 |
| SSRF leads to internal port scan |
Server-Side Request Forgery (SSRF) |
veejeey_ |
Low |
2020-03-24 |
| SSRF & unrestricted file upload on https://my.stripo.email/ |
Server-Side Request Forgery (SSRF) |
pain45 |
Critical |
2020-02-19 |
| csrf bypass using flash file + 307 redirect method at plugins endpoint |
Cross-Site Request Forgery (CSRF) |
qotoz |
Medium |
2020-02-10 |
| Able to download any hosted content on AWS S3 bucket(stripo) |
Improper Access Control - Generic |
unchained_ |
Low |
2020-02-10 |
| Authorization for wp-admin directory are vulnerable to brute force. |
Improper Restriction of Authentication Attempts |
brumens |
High |
2020-02-05 |
| No Rate Limiting on /reset-password-request/ endpoint |
Violation of Secure Design Principles |
tess |
Medium |
2020-02-04 |
| my.stripo.emai email verification bypassed and also create email templates |
Reliance on Untrusted Inputs in a Security Decision |
h51ic0pt5r |
Medium |
2020-02-04 |
| Improper Authorization |
Improper Authorization |
abdellah29 |
High |
2020-02-03 |
| CSRF - Modify Project Settings |
Cross-Site Request Forgery (CSRF) |
ahmd_halabi |
Critical |
2020-02-03 |
| Open memory dump method leaking customer information ,secret keys , password , source code & admin accounts |
Exposed Dangerous Method or Function |
homains |
Critical |
2020-01-31 |
| Tabnabbing in template comments - stripo.email |
Violation of Secure Design Principles |
renekroka |
Low |
2020-01-31 |
| Stored XSS in template comments. |
Cross-site Scripting (XSS) - Stored |
renekroka |
Medium |
2020-01-31 |
| stripo blog search SQL Injection |
SQL Injection |
bluebridsec |
Medium |
2020-01-30 |
| subdomain takeover at status-stage0.stripo.email |
Privilege Escalation |
laz0rde |
Medium |
2020-01-30 |
| Information disclosure through Server side resource forgery |
Server-Side Request Forgery (SSRF) |
checkm50 |
Medium |
2020-01-28 |
| Clickjacking on my.stripo.email for MailChimp credentials |
UI Redressing (Clickjacking) |
jasongardner |
Medium |
2020-01-08 |
| stripo.email reflected xss |
Cross-site Scripting (XSS) - Reflected |
trazer |
Medium |
2019-12-26 |
| subdomain takeover at status0.stripo.email |
Privilege Escalation |
haxorpunk |
Medium |
2019-12-23 |
| No length on password |
None supplied |
prateek_thakare |
Medium |
2019-12-23 |
| Password token leak via Host header |
Violation of Secure Design Principles |
aishkendle |
Medium |
2019-12-19 |
| OLD SESSION DOES NOT EXPIRE AFTER PASSWORD CHANGE |
None supplied |
aishkendle |
Medium |
2019-12-19 |
| Bypass email verification and create email template with the editor |
None supplied |
aishkendle |
High |
2019-12-19 |
| Redirection through referer tag |
None supplied |
b341eb9552f61203c850a10 |
Low |
2019-12-18 |
| SSRF in /cabinet/stripeapi/v1/siteInfoLookup?url=XXX |
Server-Side Request Forgery (SSRF) |
eliel |
Medium |
2019-12-18 |
| Able to change password by entering wrong old password |
Cryptographic Issues - Generic |
rutik346 |
No rating |
2019-12-18 |