Skip to content
Noroxi

Crocoblock records

23 published records for vendor crocoblock.

All records

23 records
  • Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data.

    CriticalCVSS 9.8No exploitEPSS 1%

    crocoblock · jetengineDec 15, 2021

  • WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Broken Access Control vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    crocoblock · jetelementsJun 19, 2024

  • CVE-2023-1406
    35Monitor

    JetEngine < 3.1.3.1 - Author+ Remote Code Execution

    HighCVSS 8.8No exploitEPSS 2%

    crocoblock · jetengine for elementorApr 10, 2023

  • CVE-2024-7146
    35Monitor

    JetTabs <= 2.2.3 - Authenticated (Contributor+) Arbitrary Local File Inclusion

    HighCVSS 8.8No exploitEPSS 1%

    crocoblock · jettabsAug 16, 2024

  • CVE-2024-7145
    35Monitor

    JetElements <= 2.6.20 - Authenticated (Contributor+) Arbitrary Local File Inclusion

    HighCVSS 8.8No exploitEPSS 1%

    crocoblock · jetelementsAug 16, 2024

  • WordPress JetElements For Elementor Plugin <= 2.6.10 is vulnerable to Remote Code Execution (RCE)

    HighCVSS 8.8No exploitEPSS 1%

    crocoblock · jetelementsDec 31, 2023

  • WordPress JetFormBuilder Plugin <= 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    crocoblock · jetformbuilderMay 28, 2023

  • WordPress JetElements For Elementor Plugin <= 2.6.13 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    crocoblock · jetelements for elementorDec 18, 2023

  • WordPress JetGridBuilder plugin <= 1.1.2 - Local File Inclusion vulnerability

    HighCVSS 8.5No exploitEPSS 1%

    crocoblock · jetgridbuilderAug 19, 2024

  • WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Arbitrary Attachment Download vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    crocoblock · jetelementsJun 19, 2024

  • CVE-2024-7291
    28Monitor

    JetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege Escalation

    HighCVSS 7.2No exploitEPSS 1%

    jetmonsters · jetformbuilder — dynamic blocks form builderAug 3, 2024

  • WordPress JetWidgets for Elementor and WooCommerce plugin <= 1.1.7 - Contributor+ Limited Local File Inclusion vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    crocoblock · jetwidgets for elementor and woocommerceAug 1, 2024

  • CVE-2023-0086
    26Monitor

    JetWidgets for Elementor <= 1.0.12 - Cross-Site Request Forgery to Settings Update

    MediumCVSS 6.5No exploitEPSS 0%

    crocoblock · jetwidgets for elementorJan 5, 2023

  • WordPress JetElements For Elementor plugin <= 2.6.13 - Broken Access Control vulnerability

    MediumCVSS 6.3No exploitEPSS 0%

    crocoblock · jetelementsJun 19, 2024

  • Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.

    MediumCVSS 5.4No exploitEPSS 1%

    crocoblock · jetengineAug 16, 2021

  • JetWidgets For Elementor < 1.0.9 - Contributor+ Stored XSS

    MediumCVSS 5.4No exploitEPSS 1%

    crocoblock · jetwidgets for elementorMay 5, 2021

  • CVE-2023-0034
    21Monitor

    JetWidgets For Elementor < 1.0.14 - Contributor+ Stored XSS via Shortcode

    MediumCVSS 5.4No exploitEPSS 0%

    crocoblock · jetwidgets for elementorFeb 13, 2023

  • CVE-2024-2138
    21Monitor

    JetWidgets For Elementor <= 1.0.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box Widget

    MediumCVSS 5.4No exploitEPSS 0%

    crocoblock · jetwidgets for elementorApr 9, 2024

  • CVE-2024-2507
    21Monitor

    JetWidgets For Elementor <= 1.0.16 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Button URL

    MediumCVSS 5.4No exploitEPSS 0%

    crocoblock · jetwidgets for elementorApr 9, 2024

  • CVE-2024-4626
    21Monitor

    JetWidgets For Elementor <= 1.0.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_type and id Parameters

    MediumCVSS 5.4No exploitEPSS 0%

    crocoblock · jetwidgets for elementorJun 19, 2024

  • JetWidgets For Elementor <= 1.0.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

    MediumCVSS 5.4No exploitEPSS 0%

    crocoblock · jetwidgets for elementorNov 12, 2024

  • CVE-2025-0371
    21Monitor

    Jet Elements <= 2.7.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

    MediumCVSS 5.4No exploitEPSS 0%

    crocoblock · jetelementsJan 21, 2025

  • CVE-2024-7144
    21Monitor

    JetElements <= 2.6.20 - Authenticated (Contributor+) Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    crocoblock · jetelementsAug 16, 2024