jegtheme records
16 published records for vendor jegtheme.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 18.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-639 Authorization Bypass Through User-Controlled Key2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-359 Exposure of Private Personal Information to an Unauthorized Actor1
- CWE-87 Improper Neutralization of Alternate XSS Syntax1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2022-3805Proof of concept | Jeg Elementor Kit <= 2.5.6 - Unauthenticated Authorization Bypassjegtheme · jeg elementor kit · CWE-639 | High7.5 | — | 1.6% | Dec 22, 2022 |
21Monitor | CVE-2024-3819No exploit | Jeg Elementor Kit <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Bannerjegtheme · jeg elementor kit · CWE-79 | Medium5.4 | — | 0.5% | May 2, 2024 |
21Monitor | CVE-2024-1326No exploit | Jeg Elementor Kit <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tagsjegtheme · jeg elementor kit · CWE-79 | Medium5.4 | — | 0.5% | Mar 20, 2024 |
21Monitor | CVE-2024-3161No exploit | Jeg Elementor Kit <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widgetjegtheme · jeg elementor kit · CWE-79 | Medium5.4 | — | 0.4% | May 2, 2024 |
21Monitor | CVE-2024-32721No exploit | WordPress Jeg Elementor Kit plugin <= 2.6.3 - Cross Site Scripting (XSS) vulnerabilityjegtheme · jeg elementor kit · CWE-79 | Medium5.4 | — | 0.4% | Apr 24, 2024 |
21Monitor | CVE-2024-4479No exploit | Jeg Elementor Kit <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Tabs and JKit - Accordion Widgetsjegtheme · jeg elementor kit · CWE-79 | Medium5.4 | — | 0.4% | Jun 14, 2024 |
21Monitor | CVE-2024-0334No exploit | Jeg Elementor Kit <= 2.6.4 - Authenticated (Contributor+) Cross-Site Scripting via Elementor Widget URL Custom Attributesjegtheme · jeg elementor kit · CWE-79 | Medium5.4 | — | 0.4% | May 1, 2024 |
21Monitor | CVE-2024-29101No exploit | WordPress Jeg Elementor Kit plugin <= 2.6.2 - Cross Site Scripting (XSS) vulnerabilityjegtheme · jeg elementor kit · CWE-79 | Medium5.4 | — | 0.4% | Mar 19, 2024 |
21Monitor | CVE-2024-6804No exploit | Jeg Elementor Kit <= 2.6.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Filejegtheme · jeg elementor kit · CWE-79 | Medium5.4 | — | 0.4% | Aug 27, 2024 |
21Monitor | CVE-2024-1327No exploit | Jeg Elementor Kit <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Boxjegtheme · jeg elementor kit · CWE-79 | Medium5.4 | — | 0.3% | Apr 2, 2024 |
21Monitor | CVE-2024-3162No exploit | Jeg Elementor Kit <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonialjegtheme · jeg elementor kit · CWE-87 | Medium5.4 | — | 0.3% | Apr 2, 2024 |
21Monitor | CVE-2024-10308No exploit | Jeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Countdown Widgetjegtheme · jeg elementor kit · CWE-79 | Medium5.4 | — | 0.3% | Nov 26, 2024 |
21Monitor | CVE-2024-47390No exploit | WordPress Jeg Elementor Kit plugin <= 2.6.8 - Cross Site Scripting (XSS) vulnerabilityjegtheme · jeg elementor kit · CWE-79 | Medium5.4 | — | 0.3% | Oct 5, 2024 |
17Monitor | CVE-2022-3794No exploit | Jeg Elementor Kit <= 2.5.6 - Authorization Bypassjegtheme · jeg elementor kit · CWE-639 | Medium4.3 | — | 0.6% | Dec 22, 2022 |
17Monitor | CVE-2024-8899No exploit | Jeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Sensitive Information Exposure via sg_content_templatejegtheme · jeg elementor kit · CWE-200 | Medium4.3 | — | 0.4% | Nov 26, 2024 |
17Monitor | CVE-2024-13217No exploit | Jeg Elementor Kit <= 2.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via Countdown and Off-Canvasjegtheme · jeg elementor kit · CWE-359 | Medium4.3 | — | 0.4% | Feb 27, 2025 |
- CVE-2022-380530Monitor
Jeg Elementor Kit <= 2.5.6 - Unauthenticated Authorization Bypass
HighCVSS 7.5Proof of conceptEPSS 2%jegtheme · jeg elementor kitDec 22, 2022
- CVE-2024-381921Monitor
Jeg Elementor Kit <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Banner
MediumCVSS 5.4No exploitEPSS 1%jegtheme · jeg elementor kitMay 2, 2024
- CVE-2024-132621Monitor
Jeg Elementor Kit <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags
MediumCVSS 5.4No exploitEPSS 1%jegtheme · jeg elementor kitMar 20, 2024
- CVE-2024-316121Monitor
Jeg Elementor Kit <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
MediumCVSS 5.4No exploitEPSS 0%jegtheme · jeg elementor kitMay 2, 2024
- CVE-2024-3272121Monitor
WordPress Jeg Elementor Kit plugin <= 2.6.3 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%jegtheme · jeg elementor kitApr 24, 2024
- CVE-2024-447921Monitor
Jeg Elementor Kit <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Tabs and JKit - Accordion Widgets
MediumCVSS 5.4No exploitEPSS 0%jegtheme · jeg elementor kitJun 14, 2024
- CVE-2024-033421Monitor
Jeg Elementor Kit <= 2.6.4 - Authenticated (Contributor+) Cross-Site Scripting via Elementor Widget URL Custom Attributes
MediumCVSS 5.4No exploitEPSS 0%jegtheme · jeg elementor kitMay 1, 2024
- CVE-2024-2910121Monitor
WordPress Jeg Elementor Kit plugin <= 2.6.2 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%jegtheme · jeg elementor kitMar 19, 2024
- CVE-2024-680421Monitor
Jeg Elementor Kit <= 2.6.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File
MediumCVSS 5.4No exploitEPSS 0%jegtheme · jeg elementor kitAug 27, 2024
- CVE-2024-132721Monitor
Jeg Elementor Kit <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Box
MediumCVSS 5.4No exploitEPSS 0%jegtheme · jeg elementor kitApr 2, 2024
- CVE-2024-316221Monitor
Jeg Elementor Kit <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial
MediumCVSS 5.4No exploitEPSS 0%jegtheme · jeg elementor kitApr 2, 2024
- CVE-2024-1030821Monitor
Jeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Countdown Widget
MediumCVSS 5.4No exploitEPSS 0%jegtheme · jeg elementor kitNov 26, 2024
- CVE-2024-4739021Monitor
WordPress Jeg Elementor Kit plugin <= 2.6.8 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%jegtheme · jeg elementor kitOct 5, 2024
- CVE-2022-379417Monitor
Jeg Elementor Kit <= 2.5.6 - Authorization Bypass
MediumCVSS 4.3No exploitEPSS 1%jegtheme · jeg elementor kitDec 22, 2022
- CVE-2024-889917Monitor
Jeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Sensitive Information Exposure via sg_content_template
MediumCVSS 4.3No exploitEPSS 0%jegtheme · jeg elementor kitNov 26, 2024
- CVE-2024-1321717Monitor
Jeg Elementor Kit <= 2.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via Countdown and Off-Canvas
MediumCVSS 4.3No exploitEPSS 0%jegtheme · jeg elementor kitFeb 27, 2025