Перейти к содержимому
Noroxi

Записи Crocoblock

23 опубликованных записей вендора crocoblock.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
34,8 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

23 записей
  • CVE-2021-41844
    39Наблюдать

    Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    crocoblock · jetengine15 дек. 2021 г.

  • CVE-2023-48760
    39Наблюдать

    WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Broken Access Control vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    crocoblock · jetelements19 июн. 2024 г.

  • CVE-2023-1406
    35Наблюдать

    JetEngine < 3.1.3.1 - Author+ Remote Code Execution

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    crocoblock · jetengine for elementor10 апр. 2023 г.

  • CVE-2024-7146
    35Наблюдать

    JetTabs <= 2.2.3 - Authenticated (Contributor+) Arbitrary Local File Inclusion

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    crocoblock · jettabs16 авг. 2024 г.

  • CVE-2024-7145
    35Наблюдать

    JetElements <= 2.6.20 - Authenticated (Contributor+) Arbitrary Local File Inclusion

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    crocoblock · jetelements16 авг. 2024 г.

  • CVE-2023-39157
    35Наблюдать

    WordPress JetElements For Elementor Plugin <= 2.6.10 is vulnerable to Remote Code Execution (RCE)

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    crocoblock · jetelements31 дек. 2023 г.

  • CVE-2023-33212
    35Наблюдать

    WordPress JetFormBuilder Plugin <= 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF)

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    crocoblock · jetformbuilder28 мая 2023 г.

  • CVE-2023-48762
    35Наблюдать

    WordPress JetElements For Elementor Plugin <= 2.6.13 is vulnerable to Cross Site Request Forgery (CSRF)

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    crocoblock · jetelements for elementor18 дек. 2023 г.

  • CVE-2024-43221
    34Наблюдать

    WordPress JetGridBuilder plugin <= 1.1.2 - Local File Inclusion vulnerability

    ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %

    crocoblock · jetgridbuilder19 авг. 2024 г.

  • CVE-2023-48759
    30Наблюдать

    WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Arbitrary Attachment Download vulnerability

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    crocoblock · jetelements19 июн. 2024 г.

  • CVE-2024-7291
    28Наблюдать

    JetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege Escalation

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    jetmonsters · jetformbuilder — dynamic blocks form builder3 авг. 2024 г.

  • CVE-2024-38772
    26Наблюдать

    WordPress JetWidgets for Elementor and WooCommerce plugin <= 1.1.7 - Contributor+ Limited Local File Inclusion vulnerability

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    crocoblock · jetwidgets for elementor and woocommerce1 авг. 2024 г.

  • CVE-2023-0086
    26Наблюдать

    JetWidgets for Elementor <= 1.0.12 - Cross-Site Request Forgery to Settings Update

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    crocoblock · jetwidgets for elementor5 янв. 2023 г.

  • CVE-2023-48761
    25Наблюдать

    WordPress JetElements For Elementor plugin <= 2.6.13 - Broken Access Control vulnerability

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    crocoblock · jetelements19 июн. 2024 г.

  • CVE-2021-38607
    21Наблюдать

    Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    crocoblock · jetengine16 авг. 2021 г.

  • CVE-2021-24268
    21Наблюдать

    JetWidgets For Elementor < 1.0.9 - Contributor+ Stored XSS

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    crocoblock · jetwidgets for elementor5 мая 2021 г.

  • CVE-2023-0034
    21Наблюдать

    JetWidgets For Elementor < 1.0.14 - Contributor+ Stored XSS via Shortcode

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    crocoblock · jetwidgets for elementor13 февр. 2023 г.

  • CVE-2024-2138
    21Наблюдать

    JetWidgets For Elementor <= 1.0.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box Widget

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    crocoblock · jetwidgets for elementor9 апр. 2024 г.

  • CVE-2024-2507
    21Наблюдать

    JetWidgets For Elementor <= 1.0.16 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Button URL

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    crocoblock · jetwidgets for elementor9 апр. 2024 г.

  • CVE-2024-4626
    21Наблюдать

    JetWidgets For Elementor <= 1.0.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_type and id Parameters

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    crocoblock · jetwidgets for elementor19 июн. 2024 г.

  • CVE-2024-10323
    21Наблюдать

    JetWidgets For Elementor <= 1.0.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    crocoblock · jetwidgets for elementor12 нояб. 2024 г.

  • CVE-2025-0371
    21Наблюдать

    Jet Elements <= 2.7.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    crocoblock · jetelements21 янв. 2025 г.

  • CVE-2024-7144
    21Наблюдать

    JetElements <= 2.6.20 - Authenticated (Contributor+) Stored Cross-Site Scripting

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    crocoblock · jetelements16 авг. 2024 г.