VendorsCrocoblockjetwidgets_for_elementorall versions
Vulnerabilities

Crocoblock JetWidgets for Elementor

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2023-0086
JetWidgets for Elementor <= 1.0.12 - Cross-Site Request Forgery to Settings Update
Published 2023-01-05 · Modified
6.5EPSS 0.003
CVE-2024-2138
JetWidgets For Elementor <= 1.0.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box Widget
Published 2024-04-09 · Modified
6.4EPSS 0.004
CVE-2024-2507
JetWidgets For Elementor <= 1.0.16 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Button URL
Published 2024-04-09 · Modified
6.4EPSS 0.003
CVE-2024-4626
JetWidgets For Elementor <= 1.0.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_type and id Parameters
Published 2024-06-20 · Modified
6.4EPSS 0.003
CVE-2024-10323
JetWidgets For Elementor <= 1.0.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Published 2024-11-12 · Analyzed
6.4EPSS 0.003
CVE-2021-24268
JetWidgets For Elementor < 1.0.9 - Contributor+ Stored XSS
Published 2021-05-05 · Modified
5.4EPSS 0.006
CVE-2023-0034
JetWidgets For Elementor < 1.0.14 - Contributor+ Stored XSS via Shortcode
Published 2023-02-13 · Modified
5.4EPSS 0.005