Vulnerabilities (CVE)

Filtered by vendor Crocoblock Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-38607 1 Crocoblock 1 Jetengine 2021-08-23 3.5 LOW 5.4 MEDIUM
Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.
CVE-2021-24268 1 Crocoblock 1 Jetwidgets For Elementor 2021-05-07 3.5 LOW 5.4 MEDIUM
The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.