Crocoblock

Jetengine

25 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 12:16:32
  • Zuletzt bearbeitet 20.08.2026 15:18:15

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.

  • EPSS 0.48%
  • Veröffentlicht 19.08.2026 12:38:45
  • Zuletzt bearbeitet 20.08.2026 16:17:45

Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.

  • EPSS 0.18%
  • Veröffentlicht 06.08.2026 14:27:08
  • Zuletzt bearbeitet 12.08.2026 20:58:37

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

  • EPSS 0.15%
  • Veröffentlicht 23.07.2026 11:18:44
  • Zuletzt bearbeitet 23.07.2026 16:17:50

Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.

  • EPSS 0.23%
  • Veröffentlicht 26.06.2026 14:52:52
  • Zuletzt bearbeitet 29.06.2026 15:16:42

Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.

  • EPSS 0.32%
  • Veröffentlicht 17.06.2026 04:32:05
  • Zuletzt bearbeitet 17.06.2026 04:32:05

The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check t...

  • EPSS 0.37%
  • Veröffentlicht 25.05.2026 22:34:09
  • Zuletzt bearbeitet 24.07.2026 10:10:00

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1.

  • EPSS 0.37%
  • Veröffentlicht 14.04.2026 01:25:01
  • Zuletzt bearbeitet 22.04.2026 20:23:16

The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint in all versions up to, and including, 3.8.6.1. This is due to the `_cct_search` parameter being interpolated directly into a ...

  • EPSS 0.32%
  • Veröffentlicht 24.03.2026 04:27:50
  • Zuletzt bearbeitet 24.04.2026 16:32:53

The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter being excluded from the HMAC signature validation (...

  • EPSS 0.36%
  • Veröffentlicht 13.03.2026 11:42:00
  • Zuletzt bearbeitet 22.04.2026 21:30:26

Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1.