Skip to main content

Vendor archive

crocoblock CVEs

Beta · best-effort

19 CVEs tagged to vendor crocoblock2 Critical, 4 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2025-0371

Published Jan 21, 2025

The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.7.2.1 due to insufficient input sanit…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-10323

Published Nov 12, 2024

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.0.18 due to in…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7145

Published Aug 16, 2024

The JetElements plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.20 via the 'progress_type' parameter. This makes it possible f…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7144

Published Aug 16, 2024

The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters in all versions up to, and including, 2.6.20 due to insuff…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4626

Published Jun 20, 2024

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_type’ and 'id' parameters in all versions up to, and including, 1.0.…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48761

Published Jun 19, 2024

Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-48760

Published Jun 19, 2024

Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-48759

Published Jun 19, 2024

Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-2507

Published Apr 9, 2024

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget button URL in all versions up to, and including, 1.0.16 due to insuff…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2138

Published Apr 9, 2024

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animated Box widget in all versions up to, and including, 1.0.15 due to insu…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39157

Published Dec 31, 2023

Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-48762

Published Dec 18, 2023

Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-33212

Published May 28, 2023

Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-1406

Published Apr 10, 2023

The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-0034

Published Feb 13, 2023

The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shor…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0086

Published Jan 5, 2023

The JetWidgets for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.12. This is due to missing nonce validation on…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38607

Published Aug 16, 2021

Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24268

Published May 5, 2021

The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contrib…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1