Filtered by vendor Crocoblock
Subscriptions
Filtered by product Jetengine
Subscriptions
Total
6 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-54688 | 2 Crocoblock, Wordpress | 2 Jetengine, Wordpress | 2025-08-14 | 6.5 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.7.1.2. | ||||
CVE-2023-48758 | 2 Crocoblock, Wordpress | 2 Jetengine, Wordpress | 2025-07-13 | 7.1 High |
Missing Authorization vulnerability in Crocoblock JetEngine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through 3.2.4. | ||||
CVE-2025-0369 | 2 Crocoblock, Wordpress | 2 Jetengine, Wordpress | 2025-07-12 | 6.4 Medium |
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘list_tag’ parameter in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
CVE-2023-48757 | 2 Crocoblock, Wordpress | 2 Jetengine, Wordpress | 2024-11-21 | 8.8 High |
Improper Privilege Management vulnerability in Crocoblock JetEngine allows Privilege Escalation.This issue affects JetEngine: from n/a through 3.2.4. | ||||
CVE-2021-41844 | 1 Crocoblock | 1 Jetengine | 2024-11-21 | 9.8 Critical |
Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data. | ||||
CVE-2021-38607 | 1 Crocoblock | 1 Jetengine | 2024-11-21 | 5.4 Medium |
Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input. |
Page 1 of 1.