VYPR

Jetengine

by WordPress

CVEs (32)

  • CVE-2026-52706CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.

  • CVE-2026-49075CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.

  • CVE-2026-54187CriJun 17, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.

  • CVE-2026-49084CriJun 17, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.

  • CVE-2026-49076CriJun 17, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions.

  • CVE-2026-42774CriMay 25, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1.

  • CVE-2026-32355HigMar 13, 2026
    risk 0.57cvss 8.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1.

  • CVE-2023-48757HigMay 17, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper Privilege Management vulnerability in Crocoblock JetEngine allows Privilege Escalation.This issue affects JetEngine: from n/a through 3.2.4.

  • CVE-2023-1406HigApr 10, 2023
    risk 0.57cvss 8.8epss 0.02

    The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.

  • CVE-2026-28134HigMar 5, 2026
    risk 0.55cvss 8.5epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetEngine jet-engine allows Remote Code Inclusion.This issue affects JetEngine: from n/a through <= 3.7.2.

  • CVE-2025-53194HigAug 20, 2025
    risk 0.55cvss 8.5epss 0.00

    Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Code Injection.This issue affects JetEngine: from n/a through <= 3.7.0.

  • CVE-2026-12360HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.00

    The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter…

  • CVE-2026-4352HigApr 14, 2026
    risk 0.49cvss 7.5epss 0.00

    The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint in all versions up to, and including, 3.8.6.1. This is due to the `_cct_search` parameter being interpolated directly into a SQL query string via…

  • CVE-2026-4662HigMar 24, 2026
    risk 0.49cvss 7.5epss 0.00

    The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter being excluded from the HMAC signature validation (allowing attacker-controlled…

  • CVE-2026-28082HigAug 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

  • CVE-2026-54189HigJun 17, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

  • CVE-2026-54188HigJun 17, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

  • CVE-2026-49074HigJun 17, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.

  • CVE-2025-68495HigFeb 20, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.8.0.

  • CVE-2025-67923HigJan 22, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.7.7.

Page 1 of 2