Skip to main content

Vendor/product archive

automattic / jetpack_crm CVEs

Beta · best-effort

4 CVEs tagged to automattic / jetpack_crm0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2022-3342

Published Oct 20, 2023

The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zeroBSCRM_CSVImporterLitehtml_app' function in versions up to,…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-27429

Published Jun 21, 2023

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Automattic - Jetpack CRM team Jetpack CRM plugin <= 5.4.4 versions.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-4497

Published Jan 9, 2023

The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a r…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3919

Published Dec 12, 2022

The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even w…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1