Jetformbuilder
by WordPress
Source repositories
CVEs (13)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-32525 | Cri | 0.64 | 9.9 | 0.00 | Mar 25, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.6.1. | ||
| CVE-2026-28140 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. | ||
| CVE-2025-53990 | Hig | 0.47 | 7.2 | 0.00 | Jul 16, 2025 | Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Object Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.1.2. | ||
| CVE-2024-7291 | Hig | 0.47 | 7.2 | 0.01 | Aug 3, 2024 | The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it possible for authenticated attackers, with administrator-level and above… | ||
| CVE-2023-37866 | Hig | 0.47 | 7.2 | 0.01 | May 17, 2024 | Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects JetFormBuilder: from n/a through 3.0.8. | ||
| CVE-2026-54195 | Hig | 0.46 | 7.1 | 0.00 | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions. | ||
| CVE-2026-54196 | Med | 0.44 | 6.8 | 0.00 | Jun 17, 2026 | Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions. | ||
| CVE-2026-4373 | Hig | 0.42 | 7.5 | 0.00 | Mar 21, 2026 | The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload… | ||
| CVE-2025-11991 | Med | 0.34 | 5.3 | 0.00 | Dec 16, 2025 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the run_callback function in all versions up to, and including, 3.5.3. This makes it possible for unauthenticated… | ||
| CVE-2025-64384 | Med | 0.34 | 5.3 | 0.00 | Nov 13, 2025 | Missing Authorization vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetFormBuilder: from n/a through <= 3.5.3. | ||
| CVE-2023-48763 | Med | 0.34 | 5.3 | 0.00 | Apr 24, 2024 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Crocoblock JetFormBuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through 3.1.4. | ||
| CVE-2023-33212 | Med | 0.28 | 4.3 | 0.00 | May 28, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions. | ||
| CVE-2026-13459 | Med | 0.00 | 5.3 | 0.00 | Jul 2, 2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… |
- risk 0.64cvss 9.9epss 0.00
Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.6.1.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
- risk 0.47cvss 7.2epss 0.00
Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Object Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.1.2.
- risk 0.47cvss 7.2epss 0.01
The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it possible for authenticated attackers, with administrator-level and above…
- risk 0.47cvss 7.2epss 0.01
Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects JetFormBuilder: from n/a through 3.0.8.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.
- risk 0.44cvss 6.8epss 0.00
Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions.
- risk 0.42cvss 7.5epss 0.00
The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload…
- risk 0.34cvss 5.3epss 0.00
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the run_callback function in all versions up to, and including, 3.5.3. This makes it possible for unauthenticated…
- risk 0.34cvss 5.3epss 0.00
Missing Authorization vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetFormBuilder: from n/a through <= 3.5.3.
- risk 0.34cvss 5.3epss 0.00
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Crocoblock JetFormBuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through 3.1.4.
- risk 0.28cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions.
- risk 0.00cvss 5.3epss 0.00
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…