Product
automattic jetpack
16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-54332
CVE-2024-10076
CVE-2024-10075
CVE-2024-10858
CVE-2024-9926
CVE-2023-47788
CVE-2024-4392
CVE-2023-47774
CVE-2023-45050
CVE-2023-2996
CVE-2021-24374
CVE-2015-9359
CVE-2016-10706
CVE-2016-10705
CVE-2014-0173
CVE-2011-4673
all versions
Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious sc
< 13.8
The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator featur
< 13.8
The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authoris
< 14.1
The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be
>= 13.1 and < 13.1.4
The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, suc
< 12.7
Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.
< 13.4
The Jetpack - WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi
< 12.7
Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Je
<= 12.8-a.1
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack - WP Secu
< 12.1.1
The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipula
< 9.8
The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and
< 3.4.3
The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().
< 4.0.3
The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.
<= 4.0.3
The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.
all versions
The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x
all versions
SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbit