Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jupiter X Core MEDIUM 5.4
CVE-2025-3888

The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File inclusion in all versions up to, and including, 4.8…

Fix: after 4.8.12
Fix from $1,600 2025-05-17
Jupiter X Core HIGH 8.1
CVE-2025-2105

The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8.11 via deserialization of unt…

Fix: 4.8.12+
Fix from $1,950 2025-04-26
Jupiter X Core HIGH 8.8
CVE-2025-0366

The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 vi…

Fix: 4.8.8+
Fix from $1,950 2025-02-01
Jupiter X Core MEDIUM 6.5
CVE-2025-0365

The Jupiter X Core plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.8.7 via the inline SVG feature. …

Fix: 4.8.8+
Fix from $1,600 2025-02-01
Jupiter X Core MEDIUM 5.3
CVE-2024-12316

The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_popup_action() f…

Fix: 4.8.6+
Fix from $1,600 2025-01-07
Jupiter X Core HIGH 8.8
CVE-2023-38385

Missing Authorization vulnerability in Artbees JupiterX Core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec…

Fix: 3.3.5+
Fix from $1,950 2024-12-13
Jupiter X Core CRITICAL 9.8
CVE-2024-7772

The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function i…

Fix: 4.6.6+
Fix from $2,300 2024-09-26
Jupiter X Core CRITICAL 9.8
CVE-2024-7781

The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper a…

Fix: 4.7.8+
Fix from $2,300 2024-09-26
Jupiter X Core CRITICAL 9.8
CVE-2023-38389

Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Jup…

Fix: after 3.3.8
Fix from $2,300 2024-06-21
Jupiter X Core HIGH 8.8
CVE-2023-38394

Missing Authorization vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.

Fix: 3.3.5+
Fix from $1,950 2024-06-19
Sellkit MEDIUM 5.4
CVE-2024-4608

The SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster plugin for WordPress is vulnerable to Stored Cross-Site Scri…

Fix: 2.0.0+
Fix from $1,600 2024-06-06
Jupiterx HIGH 8.8
CVE-2023-32110

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in artbees JupiterX allows PHP Local File Inclusion.This…

Fix: 3.1.0+
Fix from $1,950 2024-05-17
Jupiter X Core CRITICAL 9.8
CVE-2023-38388

Unrestricted Upload of File with Dangerous Type vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from n/a through 3.3.5.

Fix: 3.3.8+
Fix from $2,300 2024-03-26
Jupiter X Core HIGH 7.5
CVE-2023-3813

The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 4.6.6. This makes it possible for…

Fix: after 2.5.0
Fix from $1,950 2023-07-21
Jupiter HIGH 8.8
CVE-2022-1654

Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or customer-level attacker, to gai…

Fix: after 6.10.1
Fix from $1,950 2022-06-13
Jupiter HIGH 8.8
CVE-2022-1657

Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX (<= 2.0.6) Themes allow logged-in users, including subscriber-level users, to perform Pat…

Fix: after 6.10.1
Fix from $1,950 2022-06-13
Jupiterx HIGH 7.3
CVE-2022-1659

Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin register an AJAX action jupiterx_conditional_manager which can be used to call any functio…

Fix: after 2.0.6
Fix from $1,950 2022-06-13
Jupiter MEDIUM 5.4
CVE-2022-1658

Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, including users with the subscriber r…

Fix: after 6.10.1
Fix from $1,600 2022-06-13
Jupiter X Core MEDIUM 5.4
CVE-2022-1656

Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to access any of the functions regist…

Fix: after 2.0.6
Fix from $1,600 2022-06-13