Vulnerabilidades en Jetmonsters

55 resultados
Análisis Vexday

A Jetmonsters apresenta um perfil de risco modesto com 3 CVEs catalogadas, nenhuma sob exploração ativa e sem críticas confirmadas. O inventário recente mostra 2 divulgações nos últimos 90 dias, indicando descobertas contínuas, com a fraqueza dominante concentrada em CWE-266 (problemas de controle de privilégios), sugerindo foco em validação de permissões.

CVE-2024-4413CRITICALHotel Booking Lite <= 4.11.1 - Unauthenticated PHP Object InjectionEPSS 0.9%CVE-2025-30846HIGHWordPress Restaurant Menu by MotoPress plugin <= 2.4.4 - Local File Inclusion vulnerabilityEPSS 0.7%CVE-2023-1895HIGHGetwid – Gutenberg Blocks <= 1.8.3 - Authenticated(Subscriber+) Server Side Request ForgeryEPSS 0.6%CVE-2026-13459MEDIUMJetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' ParameterEPSS 0.6%CVE-2026-4373HIGHJetFormBuilder <= 3.5.6.2 - Unauthenticated Arbitrary File Read via Media FieldEPSS 0.6%CVE-2024-3342CRITICALTimetable and Event Schedule by MotoPress <= 2.4.11 - Authenticated (Contributor+) SQL InjectionEPSS 0.6%CVE-2026-9180MEDIUMMotoPress Appointment Booking <= 2.4.4 - Unauthenticated Insecure Direct Object Reference to 'payment_details.booking_id' ParameterEPSS 0.6%CVE-2024-3588MEDIUMGetwid – Gutenberg Blocks <= 2.0.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'Countdown'EPSS 0.5%CVE-2023-6963MEDIUMGetwid – Gutenberg Blocks <= 2.0.4 - Captcha BypassEPSS 0.5%CVE-2024-7291HIGHJetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege EscalationEPSS 0.5%CVE-2024-10316MEDIUMStratum – Elementor Widgets <= 1.4.4 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplatesEPSS 0.5%CVE-2026-32525CRITICALWordPress JetFormBuilder plugin <= 3.5.6.1 - Remote Code Execution (RCE) vulnerabilityEPSS 0.5%CVE-2026-12793CRITICALJetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' ParameterEPSS 0.5%CVE-2023-1910MEDIUMGetwid – Gutenberg Blocks <= 1.8.3 - Improper Authorization via get_remote_templates REST endpointEPSS 0.5%CVE-2026-8684MEDIUMMotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary Booking Notes Modification via mphb_update_booking_notes AJAX ActionEPSS 0.5%CVE-2026-73400HIGHWordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-53990HIGHWordPress JetFormBuilder plugin <= 3.5.1.2 - PHP Object Injection VulnerabilityEPSS 0.5%CVE-2026-13454MEDIUMMotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' ParameterEPSS 0.5%CVE-2024-5020MEDIUMMultiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript LibraryEPSS 0.4%CVE-2023-6959MEDIUMGetwid – Gutenberg Blocks <= 2.0.4 - Missing Authorization to Recaptcha API Key ModificationEPSS 0.4%