Crocoblock
Crocoblock Jetformbuilder: vulnerabilidades y CVE
Crocoblock Jetformbuilder tiene 21 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses16
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-102391 | Alta (7.1) | 0.25% | — | 30 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. |
| CVE-2026-92212 | Media (6.1) | 0.21% | — | 25 sept 2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field in all versions up to, and… |
| CVE-2026-19860 | Media (5.5) | 0.23% | — | 19 sept 2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a… |
| CVE-2026-12793 | Crítica (9.8) | 0.52% | — | 16 sept 2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID… |
| CVE-2026-84817 | Alta (7.1) | 0.25% | — | 8 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions. |
| CVE-2026-19862 | Media (4.8) | 0.15% | — | 6 sept 2026 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing… |
| CVE-2026-19859 | Media (6.5) | 0.20% | — | 6 sept 2026 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on… |
| CVE-2026-19861 | Media (4.7) | 0.17% | — | 5 sept 2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing… |
| CVE-2026-28140 | Alta (7.5) | 0.35% | — | 6 ago 2026 | Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. |
| CVE-2026-13459 | Media (5.3) | 0.58% | — | 2 jul 2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is… |
| CVE-2026-54196 | Media (6.8) | 0.28% | — | 17 jun 2026 | Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation. This issue affects JetFormBuilder: from n/a through 3.6.1. |
| CVE-2026-54195 | Alta (7.1) | 0.25% | — | 17 jun 2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions. |
| CVE-2026-32525 | Crítica (9.9) | 0.52% | — | 25 mar 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.6.1. |
| CVE-2026-4373 | Alta (7.5) | 0.57% | — | 21 mar 2026 | The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting… |
| CVE-2025-11991 | Media (5.3) | 0.22% | — | 16 dic 2025 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the run_callback function in all versions up to, and… |
| CVE-2025-64384 | Media (5.3) | 0.26% | — | 13 nov 2025 | Missing Authorization vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetFormBuilder: from n/a through <= 3.5.3. |
| CVE-2025-53990 | Alta (7.2) | 0.47% | — | 16 jul 2025 | Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Object Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.1.2. |
| CVE-2024-7291 | Alta (7.2) | 0.53% | — | 3 ago 2024 | The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it possible for… |
| CVE-2023-37866 | Alta (7.2) | 0.76% | — | 17 may 2024 | Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects JetFormBuilder: from n/a through 3.0.8. |
| CVE-2023-48763 | Media (5.3) | 0.37% | — | 24 abr 2024 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Crocoblock JetFormBuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through 3.1.4. |
| CVE-2023-33212 | Alta (8.8) | 0.26% | — | 28 may 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.