Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jetelements MEDIUM 5.4
CVE-2025-0371

The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.7.2.1 d…

Fix: 2.7.3+
Fix from $1,600 2025-01-21
Jetwidgets For Elementor MEDIUM 5.4
CVE-2024-10323

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, a…

Fix: 1.0.19+
Fix from $1,600 2024-11-12
Jetelements HIGH 8.8
CVE-2024-7145

The JetElements plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.20 via the 'progress_type' param…

Fix: after 2.6.20
Fix from $1,950 2024-08-16
Jetelements MEDIUM 5.4
CVE-2024-7144

The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters in all versions up to, and i…

Fix: after 2.6.20
Fix from $1,600 2024-08-16
Jetwidgets For Elementor MEDIUM 5.4
CVE-2024-4626

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_type’ and 'id' parameters in all versi…

Fix: 1.0.18+
Fix from $1,600 2024-06-20
Jetelements CRITICAL 9.8
CVE-2023-48760

Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

Fix: 2.6.13.1+
Fix from $2,300 2024-06-19
Jetelements HIGH 7.5
CVE-2023-48759

Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

Fix: 2.6.13.1+
Fix from $1,950 2024-06-19
Jetelements MEDIUM 6.3
CVE-2023-48761

Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

Fix: 2.6.13.1+
Fix from $1,600 2024-06-19
Jetwidgets For Elementor MEDIUM 5.4
CVE-2024-2507

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget button URL in all versions up to, and i…

Fix: 1.0.17+
Fix from $1,600 2024-04-09
Jetwidgets For Elementor MEDIUM 5.4
CVE-2024-2138

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animated Box widget in all versions up to, and…

Fix: 1.0.16+
Fix from $1,600 2024-04-09
Jetelements HIGH 8.8
CVE-2023-39157

Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For El…

Fix: after 2.6.10
Fix from $1,950 2023-12-31
Jetelements For Elementor HIGH 8.8
CVE-2023-48762

Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a throug…

Fix: 2.6.13.1+
Fix from $1,950 2023-12-18
Jetformbuilder HIGH 8.8
CVE-2023-33212

Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions.

Fix: 3.0.7+
Fix from $1,950 2023-05-28
Jetengine For Elementor HIGH 8.8
CVE-2023-1406

The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote c…

Fix: 3.1.3.1+
Fix from $1,950 2023-04-10
Jetwidgets For Elementor MEDIUM 5.4
CVE-2023-0034

The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back…

Fix: after 1.0.13
Fix from $1,600 2023-02-13
Jetwidgets For Elementor MEDIUM 6.5
CVE-2023-0086

The JetWidgets for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.12. This is due t…

Fix: after 1.0.12
Fix from $1,600 2023-01-05
Jetengine CRITICAL 9.8
CVE-2021-41844

Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data.

Fix: 2.9.1+
Fix from $2,300 2021-12-15
Jetengine MEDIUM 5.4
CVE-2021-38607

Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.

Fix: 2.6.1+
Fix from $1,600 2021-08-16
Jetwidgets For Elementor MEDIUM 5.4
CVE-2021-24268

The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-pr…

Fix: 1.0.9+
Fix from $1,600 2021-05-05