浏览 25+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-68906 | WordPress JNews - Video plugin <= 11.0.2 - Reflected Cross Site Scripting (XSS) vulnerability | jegtheme | JNews - Video | High | 7.1 | 2026-01-22 16:52:14 | Deep Dive |
| CVE-2025-68905 | WordPress JNews - Pay Writer plugin <= 11.0.0 - Local File Inclusion vulnerability | jegtheme | JNews - Pay Writer | High | 7.5 | 2026-01-22 16:52:14 | Deep Dive |
| CVE-2025-68904 | WordPress JNews - Frontend Submit plugin <= 11.0.0 - Reflected Cross Site Scripting (XSS) vulnerability | jegtheme | JNews - Frontend Submit | High | 7.1 | 2026-01-22 16:52:13 | Deep Dive |
| CVE-2025-14275 | Jeg Elementor Kit <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | Medium | 6.4 | 2026-01-08 02:21:16 | Deep Dive |
| CVE-2025-67591 | WordPress JNews Paywall plugin < 12.0.1 - Cross Site Request Forgery (CSRF) vulnerability | jegtheme | JNews Paywall | Medium | 4.3 | 2025-12-09 14:14:17 | Deep Dive |
| CVE-2025-67538 | WordPress JNews Gallery plugin < 12.0.1 - Cross Site Scripting (XSS) vulnerability | jegtheme | JNews Gallery | Medium | 6.5 | 2025-12-09 14:14:05 | Deep Dive |
| CVE-2025-53573 | WordPress Epic Review Plugin <= 1.0.2 - Cross Site Scripting (XSS) Vulnerability | jegtheme | Epic Review | High | 7.1 | 2025-11-06 15:54:10 | Deep Dive |
| CVE-2025-39373 | WordPress JNews theme <= 12.0.5 - Broken Access Control vulnerability | jegtheme | JNews | Medium | 5.3 | 2025-05-19 16:42:18 | Deep Dive |
| CVE-2025-2944 | Jeg Elementor Kit <= 2.6.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Button and Countdown Widgets | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | Medium | 6.4 | 2025-05-10 05:32:16 | Deep Dive |
| CVE-2024-13217 | Jeg Elementor Kit <= 2.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via Countdown and Off-Canvas | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | Medium | 4.3 | 2025-02-27 11:13:33 | Deep Dive |
| CVE-2024-10308 | Jeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Countdown Widget | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | Medium | 6.4 | 2024-11-26 11:04:31 | Deep Dive |
| CVE-2024-8899 | Jeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Sensitive Information Exposure via sg_content_template | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | Medium | 4.3 | 2024-11-26 11:04:30 | Deep Dive |
| CVE-2024-47390 | WordPress Jeg Elementor Kit plugin <= 2.6.8 - Cross Site Scripting (XSS) vulnerability | jegtheme | Jeg Elementor Kit | Medium | 6.5 | 2024-10-05 14:45:26 | Deep Dive |
| CVE-2024-6804 | Jeg Elementor Kit <= 2.6.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | Medium | 6.4 | 2024-08-27 06:48:04 | Deep Dive |
| CVE-2024-4479 | Jeg Elementor Kit <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Tabs and JKit - Accordion Widgets | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | Medium | 6.4 | 2024-06-15 02:02:01 | Deep Dive |
| CVE-2024-3161 | Jeg Elementor Kit <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | Medium | 6.4 | 2024-05-02 16:52:03 | Deep Dive |
| CVE-2024-3819 | Jeg Elementor Kit <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Banner | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | Medium | 6.4 | 2024-05-02 16:52:02 | Deep Dive |
| CVE-2024-0334 | Jeg Elementor Kit <= 2.6.4 - Authenticated (Contributor+) Cross-Site Scripting via Elementor Widget URL Custom Attributes | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | Medium | 6.4 | 2024-05-01 12:46:31 | Deep Dive |
| CVE-2024-32721 | WordPress Jeg Elementor Kit plugin <= 2.6.3 - Cross Site Scripting (XSS) vulnerability | Jegtheme | Jeg Elementor Kit | Medium | 6.5 | 2024-04-24 10:09:51 | Deep Dive |
| CVE-2024-3162 | Jeg Elementor Kit <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | Medium | 6.4 | 2024-04-03 02:32:47 | Deep Dive |