PatchSiren

Crocoblock CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Crocoblock CVE published 2026-07-13

CVE-2026-61977

CVE-2026-61977 is a MEDIUM severity vulnerability in Crocoblock JetSearch, classified as Exposure of Sensitive System Information to an Unauthorized Control Sphere. The issue affects JetSearch from n/a through <= 3.6.1.2. The CVE record was published on 2026-07-13T10:16:47.400Z and has not been modified since then. This vulnerability allows Retrieve Embedded Sensitive Data, with a CVSS score of 5.3. Users [truncated]

MEDIUM Crocoblock CVE published 2026-07-13

CVE-2026-61976

CVE-2026-61976 is a MEDIUM severity vulnerability in Crocoblock JetBlocks For Elementor jet-blocks, classified as an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability, which allows Retrieve Embedded Sensitive Data. This vulnerability affects JetBlocks For Elementor from n/a through <= 1.5.0. The issue arises from the exposure of sensitive system information, potentia [truncated]

MEDIUM Crocoblock CVE published 2026-07-13

CVE-2026-61975

CVE-2026-61975 is a MEDIUM severity vulnerability in Crocoblock JetReviews jet-reviews, affecting versions from n/a through <= 3.0.1. The vulnerability allows Retrieve Embedded Sensitive Data. Users of Crocoblock JetReviews jet-reviews should review and apply the necessary updates to prevent potential exposure of sensitive system information. The CVSS score is 5.3, and the CVSS severity is MEDIUM. The CVE [truncated]

CRITICAL Crocoblock CVE published 2026-05-25

CVE-2026-42774

A critical SQL injection vulnerability (CWE-89) in Crocoblock JetEngine, a WordPress plugin, allows unauthenticated attackers to execute arbitrary SQL commands. The vulnerability affects all versions from n/a through 3.8.8.1. With a CVSS 3.1 score of 9.3 (Critical), this represents a severe risk to WordPress sites using the affected plugin, particularly due to the network-attackable vector, low attack com [truncated]