Crocoblock kayıtları
crocoblock üreticisine ait 23 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %34,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-862 Missing Authorization3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-269 Improper Privilege Management1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
23 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2021-41844İstismar yok | Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data.crocoblock · jetengine · CWE-20 | Kritik9,8 | — | %1,1 | 15 Ara 2021 |
39İzleyin | CVE-2023-48760İstismar yok | WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Broken Access Control vulnerabilitycrocoblock · jetelements · CWE-862 | Kritik9,8 | — | %0,4 | 19 Haz 2024 |
35İzleyin | CVE-2023-1406İstismar yok | JetEngine < 3.1.3.1 - Author+ Remote Code Executioncrocoblock · jetengine for elementor · CWE-434 | Yüksek8,8 | — | %1,5 | 10 Nis 2023 |
35İzleyin | CVE-2024-7146İstismar yok | JetTabs <= 2.2.3 - Authenticated (Contributor+) Arbitrary Local File Inclusioncrocoblock · jettabs · CWE-22 | Yüksek8,8 | — | %1,0 | 16 Ağu 2024 |
35İzleyin | CVE-2024-7145İstismar yok | JetElements <= 2.6.20 - Authenticated (Contributor+) Arbitrary Local File Inclusioncrocoblock · jetelements · CWE-22 | Yüksek8,8 | — | %0,9 | 16 Ağu 2024 |
35İzleyin | CVE-2023-39157İstismar yok | WordPress JetElements For Elementor Plugin <= 2.6.10 is vulnerable to Remote Code Execution (RCE)crocoblock · jetelements · CWE-94 | Yüksek8,8 | — | %0,7 | 31 Ara 2023 |
35İzleyin | CVE-2023-33212İstismar yok | WordPress JetFormBuilder Plugin <= 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF)crocoblock · jetformbuilder · CWE-352 | Yüksek8,8 | — | %0,3 | 28 May 2023 |
35İzleyin | CVE-2023-48762İstismar yok | WordPress JetElements For Elementor Plugin <= 2.6.13 is vulnerable to Cross Site Request Forgery (CSRF)crocoblock · jetelements for elementor · CWE-352 | Yüksek8,8 | — | %0,2 | 18 Ara 2023 |
34İzleyin | CVE-2024-43221İstismar yok | WordPress JetGridBuilder plugin <= 1.1.2 - Local File Inclusion vulnerabilitycrocoblock · jetgridbuilder · CWE-22 | Yüksek8,5 | — | %0,5 | 19 Ağu 2024 |
30İzleyin | CVE-2023-48759İstismar yok | WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Arbitrary Attachment Download vulnerabilitycrocoblock · jetelements · CWE-862 | Yüksek7,5 | — | %0,4 | 19 Haz 2024 |
28İzleyin | CVE-2024-7291İstismar yok | JetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege Escalationjetmonsters · jetformbuilder — dynamic blocks form builder · CWE-269 | Yüksek7,2 | — | %0,5 | 3 Ağu 2024 |
26İzleyin | CVE-2024-38772İstismar yok | WordPress JetWidgets for Elementor and WooCommerce plugin <= 1.1.7 - Contributor+ Limited Local File Inclusion vulnerabilitycrocoblock · jetwidgets for elementor and woocommerce · CWE-22 | Orta6,5 | — | %0,5 | 1 Ağu 2024 |
26İzleyin | CVE-2023-0086İstismar yok | JetWidgets for Elementor <= 1.0.12 - Cross-Site Request Forgery to Settings Updatecrocoblock · jetwidgets for elementor · CWE-352 | Orta6,5 | — | %0,3 | 5 Oca 2023 |
25İzleyin | CVE-2023-48761İstismar yok | WordPress JetElements For Elementor plugin <= 2.6.13 - Broken Access Control vulnerabilitycrocoblock · jetelements · CWE-862 | Orta6,3 | — | %0,3 | 19 Haz 2024 |
21İzleyin | CVE-2021-38607İstismar yok | Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.crocoblock · jetengine · CWE-79 | Orta5,4 | — | %0,6 | 16 Ağu 2021 |
21İzleyin | CVE-2021-24268İstismar yok | JetWidgets For Elementor < 1.0.9 - Contributor+ Stored XSScrocoblock · jetwidgets for elementor · CWE-79 | Orta5,4 | — | %0,6 | 5 May 2021 |
21İzleyin | CVE-2023-0034İstismar yok | JetWidgets For Elementor < 1.0.14 - Contributor+ Stored XSS via Shortcodecrocoblock · jetwidgets for elementor · CWE-79 | Orta5,4 | — | %0,5 | 13 Şub 2023 |
21İzleyin | CVE-2024-2138İstismar yok | JetWidgets For Elementor <= 1.0.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box Widgetcrocoblock · jetwidgets for elementor · CWE-79 | Orta5,4 | — | %0,4 | 9 Nis 2024 |
21İzleyin | CVE-2024-2507İstismar yok | JetWidgets For Elementor <= 1.0.16 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Button URLcrocoblock · jetwidgets for elementor · CWE-79 | Orta5,4 | — | %0,3 | 9 Nis 2024 |
21İzleyin | CVE-2024-4626İstismar yok | JetWidgets For Elementor <= 1.0.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_type and id Parameterscrocoblock · jetwidgets for elementor · CWE-79 | Orta5,4 | — | %0,3 | 19 Haz 2024 |
21İzleyin | CVE-2024-10323İstismar yok | JetWidgets For Elementor <= 1.0.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uploadcrocoblock · jetwidgets for elementor · CWE-79 | Orta5,4 | — | %0,3 | 12 Kas 2024 |
21İzleyin | CVE-2025-0371İstismar yok | Jet Elements <= 2.7.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgetscrocoblock · jetelements · CWE-79 | Orta5,4 | — | %0,3 | 21 Oca 2025 |
21İzleyin | CVE-2024-7144İstismar yok | JetElements <= 2.6.20 - Authenticated (Contributor+) Stored Cross-Site Scriptingcrocoblock · jetelements · CWE-79 | Orta5,4 | — | %0,3 | 16 Ağu 2024 |
- CVE-2021-4184439İzleyin
Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data.
KritikCVSS 9,8İstismar yokEPSS %1crocoblock · jetengine15 Ara 2021
- CVE-2023-4876039İzleyin
WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Broken Access Control vulnerability
KritikCVSS 9,8İstismar yokEPSS %0crocoblock · jetelements19 Haz 2024
- CVE-2023-140635İzleyin
JetEngine < 3.1.3.1 - Author+ Remote Code Execution
YüksekCVSS 8,8İstismar yokEPSS %2crocoblock · jetengine for elementor10 Nis 2023
- CVE-2024-714635İzleyin
JetTabs <= 2.2.3 - Authenticated (Contributor+) Arbitrary Local File Inclusion
YüksekCVSS 8,8İstismar yokEPSS %1crocoblock · jettabs16 Ağu 2024
- CVE-2024-714535İzleyin
JetElements <= 2.6.20 - Authenticated (Contributor+) Arbitrary Local File Inclusion
YüksekCVSS 8,8İstismar yokEPSS %1crocoblock · jetelements16 Ağu 2024
- CVE-2023-3915735İzleyin
WordPress JetElements For Elementor Plugin <= 2.6.10 is vulnerable to Remote Code Execution (RCE)
YüksekCVSS 8,8İstismar yokEPSS %1crocoblock · jetelements31 Ara 2023
- CVE-2023-3321235İzleyin
WordPress JetFormBuilder Plugin <= 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0crocoblock · jetformbuilder28 May 2023
- CVE-2023-4876235İzleyin
WordPress JetElements For Elementor Plugin <= 2.6.13 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0crocoblock · jetelements for elementor18 Ara 2023
- CVE-2024-4322134İzleyin
WordPress JetGridBuilder plugin <= 1.1.2 - Local File Inclusion vulnerability
YüksekCVSS 8,5İstismar yokEPSS %1crocoblock · jetgridbuilder19 Ağu 2024
- CVE-2023-4875930İzleyin
WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Arbitrary Attachment Download vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0crocoblock · jetelements19 Haz 2024
- CVE-2024-729128İzleyin
JetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege Escalation
YüksekCVSS 7,2İstismar yokEPSS %1jetmonsters · jetformbuilder — dynamic blocks form builder3 Ağu 2024
- CVE-2024-3877226İzleyin
WordPress JetWidgets for Elementor and WooCommerce plugin <= 1.1.7 - Contributor+ Limited Local File Inclusion vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0crocoblock · jetwidgets for elementor and woocommerce1 Ağu 2024
- CVE-2023-008626İzleyin
JetWidgets for Elementor <= 1.0.12 - Cross-Site Request Forgery to Settings Update
OrtaCVSS 6,5İstismar yokEPSS %0crocoblock · jetwidgets for elementor5 Oca 2023
- CVE-2023-4876125İzleyin
WordPress JetElements For Elementor plugin <= 2.6.13 - Broken Access Control vulnerability
OrtaCVSS 6,3İstismar yokEPSS %0crocoblock · jetelements19 Haz 2024
- CVE-2021-3860721İzleyin
Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.
OrtaCVSS 5,4İstismar yokEPSS %1crocoblock · jetengine16 Ağu 2021
- CVE-2021-2426821İzleyin
JetWidgets For Elementor < 1.0.9 - Contributor+ Stored XSS
OrtaCVSS 5,4İstismar yokEPSS %1crocoblock · jetwidgets for elementor5 May 2021
- CVE-2023-003421İzleyin
JetWidgets For Elementor < 1.0.14 - Contributor+ Stored XSS via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %0crocoblock · jetwidgets for elementor13 Şub 2023
- CVE-2024-213821İzleyin
JetWidgets For Elementor <= 1.0.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box Widget
OrtaCVSS 5,4İstismar yokEPSS %0crocoblock · jetwidgets for elementor9 Nis 2024
- CVE-2024-250721İzleyin
JetWidgets For Elementor <= 1.0.16 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Button URL
OrtaCVSS 5,4İstismar yokEPSS %0crocoblock · jetwidgets for elementor9 Nis 2024
- CVE-2024-462621İzleyin
JetWidgets For Elementor <= 1.0.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_type and id Parameters
OrtaCVSS 5,4İstismar yokEPSS %0crocoblock · jetwidgets for elementor19 Haz 2024
- CVE-2024-1032321İzleyin
JetWidgets For Elementor <= 1.0.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
OrtaCVSS 5,4İstismar yokEPSS %0crocoblock · jetwidgets for elementor12 Kas 2024
- CVE-2025-037121İzleyin
Jet Elements <= 2.7.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
OrtaCVSS 5,4İstismar yokEPSS %0crocoblock · jetelements21 Oca 2025
- CVE-2024-714421İzleyin
JetElements <= 2.6.20 - Authenticated (Contributor+) Stored Cross-Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %0crocoblock · jetelements16 Ağu 2024