Extension WordPress
Vulnérabilités Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation
Cette page rassemble les failles publiées pour Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation
8 fiches
Jetpack CRM <= 6.7.0 – Unauthenticated Local File Inclusion
The Jetpack CRM plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.7.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution…
*-6.7.0
6.7.1
16/02/2026
Jetpackcrm Ext Woo Connect < 2.13 – Sensitive Information Exposure
Multiple plugins for WordPress are vulnerable to Sensitive Information Exposure in various versions via invoices. This makes it possible for unauthenticated attackers to extract sensitive data including from those invoices.
[*, 4.2.4)
4.2.4
28/10/2024
Jetpack CRM <= 5.5.0 – Authenticated (Client+) Stored Cross-Site Scripting
The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the client phone number field in versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for…
*-5.5.0
5.5.1
12/09/2023
Jetpack CRM <= 5.5.0 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with…
*-5.5.0
5.5.1
12/09/2023
Jetpack CRM <= 5.3.1 – Cross-Site Request Forgery and PHAR Deserialization
The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zeroBSCRM_CSVImporterLitehtml_app' function in versions up to, and including, 5.3.1. While the function performs a nonce check, steps 2 and 3 of…
*-5.3.1
5.4.0
18/04/2023
Jetpack CRM <= 5.4.4 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with…
*-5.4.4
5.5.0
05/03/2023
Jetpack CRM <= 5.4.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 5.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-5.4.4
5.5
19/12/2022
Jetpack CRM <= 5.4.2 – Authenticated (Administrator+) Cross-Site Scripting
The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings in versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-5.4.2
5.4.3
21/11/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.