VYPR

Jet Engine

by WordPress

CVEs (2)

  • CVE-2026-42774CriMay 25, 2026
    risk 0.60cvss 9.3epss

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1.

  • CVE-2025-0369MedJan 18, 2025
    risk 0.42cvss 6.4epss 0.00

    The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘list_tag’ parameter in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…