Crocoblock records
23 published records for vendor crocoblock.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 34.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-862 Missing Authorization3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-269 Improper Privilege Management1
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-41844No exploit | Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data.crocoblock · jetengine · CWE-20 | Critical9.8 | — | 1.1% | Dec 15, 2021 |
39Monitor | CVE-2023-48760No exploit | WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Broken Access Control vulnerabilitycrocoblock · jetelements · CWE-862 | Critical9.8 | — | 0.4% | Jun 19, 2024 |
35Monitor | CVE-2023-1406No exploit | JetEngine < 3.1.3.1 - Author+ Remote Code Executioncrocoblock · jetengine for elementor · CWE-434 | High8.8 | — | 1.5% | Apr 10, 2023 |
35Monitor | CVE-2024-7146No exploit | JetTabs <= 2.2.3 - Authenticated (Contributor+) Arbitrary Local File Inclusioncrocoblock · jettabs · CWE-22 | High8.8 | — | 1.0% | Aug 16, 2024 |
35Monitor | CVE-2024-7145No exploit | JetElements <= 2.6.20 - Authenticated (Contributor+) Arbitrary Local File Inclusioncrocoblock · jetelements · CWE-22 | High8.8 | — | 0.9% | Aug 16, 2024 |
35Monitor | CVE-2023-39157No exploit | WordPress JetElements For Elementor Plugin <= 2.6.10 is vulnerable to Remote Code Execution (RCE)crocoblock · jetelements · CWE-94 | High8.8 | — | 0.7% | Dec 31, 2023 |
35Monitor | CVE-2023-33212No exploit | WordPress JetFormBuilder Plugin <= 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF)crocoblock · jetformbuilder · CWE-352 | High8.8 | — | 0.3% | May 28, 2023 |
35Monitor | CVE-2023-48762No exploit | WordPress JetElements For Elementor Plugin <= 2.6.13 is vulnerable to Cross Site Request Forgery (CSRF)crocoblock · jetelements for elementor · CWE-352 | High8.8 | — | 0.2% | Dec 18, 2023 |
34Monitor | CVE-2024-43221No exploit | WordPress JetGridBuilder plugin <= 1.1.2 - Local File Inclusion vulnerabilitycrocoblock · jetgridbuilder · CWE-22 | High8.5 | — | 0.5% | Aug 19, 2024 |
30Monitor | CVE-2023-48759No exploit | WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Arbitrary Attachment Download vulnerabilitycrocoblock · jetelements · CWE-862 | High7.5 | — | 0.4% | Jun 19, 2024 |
28Monitor | CVE-2024-7291No exploit | JetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege Escalationjetmonsters · jetformbuilder — dynamic blocks form builder · CWE-269 | High7.2 | — | 0.5% | Aug 3, 2024 |
26Monitor | CVE-2024-38772No exploit | WordPress JetWidgets for Elementor and WooCommerce plugin <= 1.1.7 - Contributor+ Limited Local File Inclusion vulnerabilitycrocoblock · jetwidgets for elementor and woocommerce · CWE-22 | Medium6.5 | — | 0.5% | Aug 1, 2024 |
26Monitor | CVE-2023-0086No exploit | JetWidgets for Elementor <= 1.0.12 - Cross-Site Request Forgery to Settings Updatecrocoblock · jetwidgets for elementor · CWE-352 | Medium6.5 | — | 0.3% | Jan 5, 2023 |
25Monitor | CVE-2023-48761No exploit | WordPress JetElements For Elementor plugin <= 2.6.13 - Broken Access Control vulnerabilitycrocoblock · jetelements · CWE-862 | Medium6.3 | — | 0.3% | Jun 19, 2024 |
21Monitor | CVE-2021-38607No exploit | Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.crocoblock · jetengine · CWE-79 | Medium5.4 | — | 0.6% | Aug 16, 2021 |
21Monitor | CVE-2021-24268No exploit | JetWidgets For Elementor < 1.0.9 - Contributor+ Stored XSScrocoblock · jetwidgets for elementor · CWE-79 | Medium5.4 | — | 0.6% | May 5, 2021 |
21Monitor | CVE-2023-0034No exploit | JetWidgets For Elementor < 1.0.14 - Contributor+ Stored XSS via Shortcodecrocoblock · jetwidgets for elementor · CWE-79 | Medium5.4 | — | 0.5% | Feb 13, 2023 |
21Monitor | CVE-2024-2138No exploit | JetWidgets For Elementor <= 1.0.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box Widgetcrocoblock · jetwidgets for elementor · CWE-79 | Medium5.4 | — | 0.4% | Apr 9, 2024 |
21Monitor | CVE-2024-2507No exploit | JetWidgets For Elementor <= 1.0.16 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Button URLcrocoblock · jetwidgets for elementor · CWE-79 | Medium5.4 | — | 0.3% | Apr 9, 2024 |
21Monitor | CVE-2024-4626No exploit | JetWidgets For Elementor <= 1.0.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_type and id Parameterscrocoblock · jetwidgets for elementor · CWE-79 | Medium5.4 | — | 0.3% | Jun 19, 2024 |
21Monitor | CVE-2024-10323No exploit | JetWidgets For Elementor <= 1.0.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uploadcrocoblock · jetwidgets for elementor · CWE-79 | Medium5.4 | — | 0.3% | Nov 12, 2024 |
21Monitor | CVE-2025-0371No exploit | Jet Elements <= 2.7.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgetscrocoblock · jetelements · CWE-79 | Medium5.4 | — | 0.3% | Jan 21, 2025 |
21Monitor | CVE-2024-7144No exploit | JetElements <= 2.6.20 - Authenticated (Contributor+) Stored Cross-Site Scriptingcrocoblock · jetelements · CWE-79 | Medium5.4 | — | 0.3% | Aug 16, 2024 |
- CVE-2021-4184439Monitor
Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data.
CriticalCVSS 9.8No exploitEPSS 1%crocoblock · jetengineDec 15, 2021
- CVE-2023-4876039Monitor
WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Broken Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 0%crocoblock · jetelementsJun 19, 2024
- CVE-2023-140635Monitor
JetEngine < 3.1.3.1 - Author+ Remote Code Execution
HighCVSS 8.8No exploitEPSS 2%crocoblock · jetengine for elementorApr 10, 2023
- CVE-2024-714635Monitor
JetTabs <= 2.2.3 - Authenticated (Contributor+) Arbitrary Local File Inclusion
HighCVSS 8.8No exploitEPSS 1%crocoblock · jettabsAug 16, 2024
- CVE-2024-714535Monitor
JetElements <= 2.6.20 - Authenticated (Contributor+) Arbitrary Local File Inclusion
HighCVSS 8.8No exploitEPSS 1%crocoblock · jetelementsAug 16, 2024
- CVE-2023-3915735Monitor
WordPress JetElements For Elementor Plugin <= 2.6.10 is vulnerable to Remote Code Execution (RCE)
HighCVSS 8.8No exploitEPSS 1%crocoblock · jetelementsDec 31, 2023
- CVE-2023-3321235Monitor
WordPress JetFormBuilder Plugin <= 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%crocoblock · jetformbuilderMay 28, 2023
- CVE-2023-4876235Monitor
WordPress JetElements For Elementor Plugin <= 2.6.13 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%crocoblock · jetelements for elementorDec 18, 2023
- CVE-2024-4322134Monitor
WordPress JetGridBuilder plugin <= 1.1.2 - Local File Inclusion vulnerability
HighCVSS 8.5No exploitEPSS 1%crocoblock · jetgridbuilderAug 19, 2024
- CVE-2023-4875930Monitor
WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Arbitrary Attachment Download vulnerability
HighCVSS 7.5No exploitEPSS 0%crocoblock · jetelementsJun 19, 2024
- CVE-2024-729128Monitor
JetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege Escalation
HighCVSS 7.2No exploitEPSS 1%jetmonsters · jetformbuilder — dynamic blocks form builderAug 3, 2024
- CVE-2024-3877226Monitor
WordPress JetWidgets for Elementor and WooCommerce plugin <= 1.1.7 - Contributor+ Limited Local File Inclusion vulnerability
MediumCVSS 6.5No exploitEPSS 0%crocoblock · jetwidgets for elementor and woocommerceAug 1, 2024
- CVE-2023-008626Monitor
JetWidgets for Elementor <= 1.0.12 - Cross-Site Request Forgery to Settings Update
MediumCVSS 6.5No exploitEPSS 0%crocoblock · jetwidgets for elementorJan 5, 2023
- CVE-2023-4876125Monitor
WordPress JetElements For Elementor plugin <= 2.6.13 - Broken Access Control vulnerability
MediumCVSS 6.3No exploitEPSS 0%crocoblock · jetelementsJun 19, 2024
- CVE-2021-3860721Monitor
Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.
MediumCVSS 5.4No exploitEPSS 1%crocoblock · jetengineAug 16, 2021
- CVE-2021-2426821Monitor
JetWidgets For Elementor < 1.0.9 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%crocoblock · jetwidgets for elementorMay 5, 2021
- CVE-2023-003421Monitor
JetWidgets For Elementor < 1.0.14 - Contributor+ Stored XSS via Shortcode
MediumCVSS 5.4No exploitEPSS 0%crocoblock · jetwidgets for elementorFeb 13, 2023
- CVE-2024-213821Monitor
JetWidgets For Elementor <= 1.0.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box Widget
MediumCVSS 5.4No exploitEPSS 0%crocoblock · jetwidgets for elementorApr 9, 2024
- CVE-2024-250721Monitor
JetWidgets For Elementor <= 1.0.16 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Button URL
MediumCVSS 5.4No exploitEPSS 0%crocoblock · jetwidgets for elementorApr 9, 2024
- CVE-2024-462621Monitor
JetWidgets For Elementor <= 1.0.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_type and id Parameters
MediumCVSS 5.4No exploitEPSS 0%crocoblock · jetwidgets for elementorJun 19, 2024
- CVE-2024-1032321Monitor
JetWidgets For Elementor <= 1.0.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
MediumCVSS 5.4No exploitEPSS 0%crocoblock · jetwidgets for elementorNov 12, 2024
- CVE-2025-037121Monitor
Jet Elements <= 2.7.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
MediumCVSS 5.4No exploitEPSS 0%crocoblock · jetelementsJan 21, 2025
- CVE-2024-714421Monitor
JetElements <= 2.6.20 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%crocoblock · jetelementsAug 16, 2024