Crocoblock
Crocoblock Jetengine: vulnerabilidades y CVE
Crocoblock Jetengine tiene 39 vulnerabilidades publicadas, 29 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE39
Últimos 12 meses29
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-97238 | Media (5.5) | 0.18% | — | 30 sept 2026 | Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. |
| CVE-2026-97237 | Alta (7.1) | 0.25% | — | 30 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. |
| CVE-2026-81760 | Alta (7.1) | 0.25% | — | 28 ago 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2. |
| CVE-2026-66581 | Alta (7.1) | 0.25% | — | 20 ago 2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. |
| CVE-2026-66613 | Crítica (9.8) | 0.86% | — | 19 ago 2026 | Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. |
| CVE-2026-18202 | Media (6.8) | 0.43% | — | 19 ago 2026 | The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a… |
| CVE-2026-17019 | Media (6.1) | 0.27% | — | 10 ago 2026 | The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a… |
| CVE-2026-28082 | Alta (7.1) | 0.25% | — | 6 ago 2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. |
| CVE-2026-14864 | Media (5.4) | 0.23% | — | 2 ago 2026 | The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site… |
| CVE-2026-65467 | Media (4.9) | 0.19% | — | 23 jul 2026 | Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. |
| CVE-2026-56068 | Crítica (9.3) | 0.40% | — | 26 jun 2026 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions. |
| CVE-2026-54189 | Alta (7.1) | 0.25% | — | 17 jun 2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. |
| CVE-2026-54188 | Alta (7.1) | 0.25% | — | 17 jun 2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. |
| CVE-2026-54187 | Crítica (9.3) | 0.40% | — | 17 jun 2026 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. |
| CVE-2026-52706 | Crítica (9.8) | 0.56% | — | 17 jun 2026 | Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions. |
| CVE-2026-49084 | Crítica (9.3) | 0.40% | — | 17 jun 2026 | Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions. |
| CVE-2026-49076 | Crítica (9.3) | 0.40% | — | 17 jun 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine jet-engine allows Blind SQL Injection.This issue affects JetEngine: from n/a through 3.8.9.1. |
| CVE-2026-49075 | Crítica (9.8) | 0.56% | — | 17 jun 2026 | Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. |
| CVE-2026-49074 | Alta (7.1) | 0.25% | — | 17 jun 2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions. |
| CVE-2026-12360 | Alta (7.5) | 0.32% | — | 17 jun 2026 | The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from… |
| CVE-2026-42774 | Crítica (9.3) | 0.40% | — | 25 may 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1. |
| CVE-2026-4352 | Alta (7.5) | 0.46% | — | 14 abr 2026 | The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint in all versions up to, and including, 3.8.6.1. This is due to the `_cct_search` parameter… |
| CVE-2026-4662 | Alta (7.5) | 0.54% | — | 24 mar 2026 | The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter being excluded from… |
| CVE-2026-32355 | Alta (8.8) | 0.52% | — | 13 mar 2026 | Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1. |
| CVE-2026-28134 | Alta (8.5) | 0.39% | — | 5 mar 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetEngine jet-engine allows Remote Code Inclusion.This issue affects JetEngine: from n/a through <= 3.7.2. |
| CVE-2025-68495 | Alta (7.1) | 0.19% | — | 20 feb 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.8.0. |
| CVE-2025-67923 | Alta (7.1) | 0.29% | — | 22 ene 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.7.7. |
| CVE-2025-69333 | Media (4.3) | 0.19% | — | 7 ene 2026 | Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.8.1.1. |
| CVE-2025-49938 | Media (6.5) | 0.22% | — | 22 oct 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Stored XSS.This issue affects JetEngine: from n/a through <= 3.7.3. |
| CVE-2025-53196 | Media (6.5) | 0.50% | — | 20 ago 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetEngine jet-engine allows Retrieve Embedded Sensitive Data.This issue affects JetEngine: from n/a through <= 3.7.0. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.