cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forjetformbuilder jetformbuilder

Direction: ascending
Jun 06, 2024

JetFormBuilder — Dynamic Blocks Form Builder # CVE-2023-48763

CVE, Research URL

CVE-2023-48763

Date
Apr 24, 2024
Research Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Crocoblock JetFormBuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through 3.1.4.
Affected versions
Min -, max -.
Status
vulnerable

JetFormBuilder — Dynamic Blocks Form Builder # CVE-2023-33212

CVE, Research URL

CVE-2023-33212

Date
May 28, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions.
Affected versions
Min -, max -.
Status
vulnerable

JetFormBuilder — Dynamic Blocks Form Builder # CVE-2023-37866

CVE, Research URL

CVE-2023-37866

Date
May 17, 2024
Research Description
Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects JetFormBuilder: from n/a through 3.0.8.
Affected versions
Min -, max -.
Status
vulnerable
Aug 04, 2024

JetFormBuilder — Dynamic Blocks Form Builder # CVE-2024-7291

CVE, Research URL

CVE-2024-7291

Date
Aug 03, 2024
Research Description
The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it possible for authenticated attackers, with administrator-level and above permissions, to register as super-admins on the sites configured as multi-sites.
Affected versions
Min -, max -.
Status
vulnerable
Jul 20, 2025

JetFormBuilder — Dynamic Blocks Form Builder # CVE-2025-53990

CVE, Research URL

CVE-2025-53990

Date
Jul 16, 2025
Research Description
Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder allows Object Injection. This issue affects JetFormBuilder: from n/a through 3.5.1.2.
Affected versions
Min -, max -.
Status
vulnerable