JetElements

Explore JetElements vulnerabilities across all versions. Currently tracking 17 known vulnerabilities, including severity, impact, and patch status.

01234567891003.08.2023Today03.08.20238.8JetElements <= 2.6.10 - Authenticated (Contributor+) Remote Code Execution CVSS 8.8 · 03.08.202328.11.20237.3Multiple Plugins by Crocoblock <= (Various Versions) - Missing Authorization to Unauthenticated Unauthorized Action CVSS 7.3 · 28.11.20236.3Multiple Plugins by Crocoblock <= (Various Versions) - Missing Authorization CVSS 6.3 · 28.11.20235.3JetElements For Elementor <= 2.6.13 - Missing Authorization to Unauthenticated Arbitrary Attachment Download CVSS 5.3 · 28.11.20234.3Multiple Plugins by Crocoblock <= (Various Versions) - Cross-Site Request Forgery CVSS 4.3 · 28.11.202315.08.20248.8JetElements <= 2.6.20 - Authenticated (Contributor+) Arbitrary Local File Inclusion CVSS 8.8 · 15.08.20246.4JetElements <= 2.6.20 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 15.08.202420.01.20256.4Jet Elements <= 2.7.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets CVSS 6.4 · 20.01.202517.04.20256.4JetElements For Elementor <= 2.7.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 17.04.20255.3JetElements For Elementor <= 2.7.4.1 - Missing Authorization CVSS 5.3 · 17.04.202516.07.20256.4JetElements For Elementor <= 2.7.7 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 16.07.20254.3JetElements For Elementor <= 2.7.7 - Authenticated (Subscriber+) Information Disclosure CVSS 4.3 · 16.07.202503.08.20256.4JetElements For Elementor <= 2.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 03.08.202514.08.20256.4JetElements For Elementor <= 2.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 14.08.202506.11.20256.4JetElements For Elementor <= 2.7.12 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 06.11.202530.12.20256.4JetElements For Elementor <= 2.7.12.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 30.12.202522.07.20266.4JetElements <= 2.9.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 22.07.2026

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

17

Get automatic notifications for all JetElements vulnerabilities before they are exploited.

Vulnerability Records

17 records
2026-07-22 00:00CVE-2026-65465
6.4
Medium
Ananda DhakalYes
2025-12-30 05:20CVE-2026-24958
6.4
Medium
BondsYes
2025-11-06 00:00CVE-2025-64355
6.4
Medium
BondsYes
2025-08-14 00:00CVE-2025-55714
6.4
Medium
stealthcopterYes
2025-08-03 00:00CVE-2025-49939
6.4
Medium
stealthcopterYes
2025-07-16 00:00CVE-2025-53982
6.4
Medium
stealthcopterYes
2025-07-16 00:00CVE-2025-53983
4.3
Medium
stealthcopterYes
2025-04-17 00:00CVE-2025-39448
6.4
Medium
stealthcopterYes
2025-04-17 00:00CVE-2025-39447
5.3
Medium
stealthcopterYes
2025-01-20 20:12CVE-2025-0371
6.4
Medium
stealthcopterYes
Showing 1–10 of 17 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C