← back
CVE-2026-17019mediumCWE-79

JetEngine < 3.8.13.1 - Unauthenticated Stored XSS via Form File Upload (SVG)

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 6.1epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Unknown · JetEngine
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.