Software
jetpack
Aggregate across all detected versions
Total Hosts
0
distinct hosts
Versions Seen
0
Countries
0
Known CVEs
16
known CVEs
Top Countries
No geolocated hosts.
Top ASNs
No attributed hosts.
CVE Matches
| CVE | CVSS | Severity | Summary |
|---|---|---|---|
| CVE-2023-2996 | 8.8 | N/A | The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site,... |
| CVE-2011-4673 | 7.5 | HIGH | SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id p... |
| CVE-2023-45050 | 6.5 | N/A | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack – WP Security, Backup, Speed, & Growth... |
| CVE-2024-4392 | 6.4 | N/A | The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all v... |
| CVE-2015-9359 | 6.1 | N/A | The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg(). |
| CVE-2016-10705 | 6.1 | N/A | The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module. |
| CVE-2016-10706 | 6.1 | N/A | The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link. |
| CVE-2023-54332 | 6.1 | N/A | Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id para... |
| CVE-2024-10858 | 6.1 | N/A | The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XS... |
| CVE-2024-10076 | 5.9 | N/A | The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs t... |
| CVE-2014-0173 | 5.8 | MEDIUM | The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5... |
| CVE-2024-10075 | 5.6 | N/A | The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow un... |
| CVE-2023-47774 | 5.4 | N/A | Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7. |
| CVE-2021-24374 | 5.3 | N/A | The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the... |
| CVE-2023-47788 | 4.3 | N/A | Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7. |
| CVE-2024-9926 | 4.3 | N/A | The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitr... |