Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-0371 The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.7.2.1 d… Jetelements 2.7.3+ Fix from $1,6002025-01-21 MEDIUM 5.4 CVE-2024-10323 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, a… Jetwidgets For Elementor 1.0.19+ Fix from $1,6002024-11-12 HIGH 8.8 CVE-2024-7145 The JetElements plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.20 via the 'progress_type' param… Jetelements after 2.6.20 Fix from $1,9502024-08-16 MEDIUM 5.4 CVE-2024-7144 The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters in all versions up to, and i… Jetelements after 2.6.20 Fix from $1,6002024-08-16 MEDIUM 5.4 CVE-2024-4626 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_type’ and 'id' parameters in all versi… Jetwidgets For Elementor 1.0.18+ Fix from $1,6002024-06-20 CRITICAL 9.8 CVE-2023-48760 Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13. Jetelements 2.6.13.1+ Fix from $2,3002024-06-19 HIGH 7.5 CVE-2023-48759 Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13. Jetelements 2.6.13.1+ Fix from $1,9502024-06-19 MEDIUM 6.3 CVE-2023-48761 Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13. Jetelements 2.6.13.1+ Fix from $1,6002024-06-19 MEDIUM 5.4 CVE-2024-2507 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget button URL in all versions up to, and i… Jetwidgets For Elementor 1.0.17+ Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2024-2138 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animated Box widget in all versions up to, and… Jetwidgets For Elementor 1.0.16+ Fix from $1,6002024-04-09 HIGH 8.8 CVE-2023-39157 Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For El… Jetelements after 2.6.10 Fix from $1,9502023-12-31 HIGH 8.8 CVE-2023-48762 Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a throug… Jetelements For Elementor 2.6.13.1+ Fix from $1,9502023-12-18 HIGH 8.8 CVE-2023-33212 Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions. Jetformbuilder 3.0.7+ Fix from $1,9502023-05-28 HIGH 8.8 CVE-2023-1406 The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote c… Jetengine For Elementor 3.1.3.1+ Fix from $1,9502023-04-10 MEDIUM 5.4 CVE-2023-0034 The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back… Jetwidgets For Elementor after 1.0.13 Fix from $1,6002023-02-13 MEDIUM 6.5 CVE-2023-0086 The JetWidgets for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.12. This is due t… Jetwidgets For Elementor after 1.0.12 Fix from $1,6002023-01-05 CRITICAL 9.8 CVE-2021-41844 Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data. Jetengine 2.9.1+ Fix from $2,3002021-12-15 MEDIUM 5.4 CVE-2021-38607 Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input. Jetengine 2.6.1+ Fix from $1,6002021-08-16 MEDIUM 5.4 CVE-2021-24268 The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-pr… Jetwidgets For Elementor 1.0.9+ Fix from $1,6002021-05-05