Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

roxnor — Vulnerabilities & Security Advisories 82

Browse all 82 CVE security advisories affecting roxnor. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Roxnor operates as a specialized provider of network security solutions, primarily focusing on intrusion detection and prevention systems designed to monitor and secure enterprise network traffic. Historical security audits have identified a significant volume of vulnerabilities within its software infrastructure, with 76 Common Vulnerabilities and Exposures currently on record. These flaws predominantly involve remote code execution and cross-site scripting, allowing attackers to potentially bypass authentication mechanisms or execute arbitrary commands on affected devices. Privilege escalation vulnerabilities have also been documented, enabling lower-privileged users to gain administrative control. While specific major public incidents remain largely contained within technical disclosure reports, the high count of disclosed CVEs indicates persistent challenges in the product’s secure development lifecycle. Organizations utilizing Roxnor appliances are advised to apply vendor patches promptly to mitigate risks associated with these known exploitation vectors and ensure continuous network integrity.

CVE ID Title CVSS Severity Published
CVE-2025-60106 WordPress EmailKit Plugin <= 1.6.0 - Arbitrary Content Deletion Vulnerability — EmailKit CWE-862 4.9 Medium 2025-09-26
CVE-2025-10173 ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.3 - Insufficient Authorization to Authenticated (Editor+) Settings Update — ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution CWE-862 2.7 Low 2025-09-26
CVE-2025-48302 WordPress FundEngine Plugin <= 1.7.4 - Local File Inclusion Vulnerability — FundEngine CWE-98 7.5 High 2025-08-20
CVE-2025-5684 MetForm <= 4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via `mf-template` DOM Element — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor CWE-79 6.4 Medium 2025-07-29
CVE-2025-3614 ElementsKit Elementor Addons and Templates <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Widget — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor CWE-79 6.4 Medium 2025-07-24
CVE-2025-4479 ElementsKit Lite <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor CWE-79 6.4 Medium 2025-06-19
CVE-2025-47459 WordPress WP Fundraising Donation and Crowdfunding Platform plugin <= 1.7.3 - Cross Site Request Forgery (CSRF) Vulnerability — FundEngine CWE-352 4.3 Medium 2025-05-07
CVE-2024-11180 ElementsKit Elementor addons <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor CWE-79 6.4 Medium 2025-03-29
CVE-2025-30914 WordPress Metform Elementor Contact Form Builder plugin <= 3.9.7 - Server Side Request Forgery (SSRF) vulnerability — Metform CWE-918 4.4 Medium 2025-03-27
CVE-2025-1506 Wp Social Login and Register Social Counter <= 3.1.0 - Cross-Site Request Forgery to Settings Update — Wp Social Login and Register Social Counter CWE-352 4.3 Medium 2025-02-28
CVE-2025-0968 ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor CWE-284 5.3 Medium 2025-02-19
CVE-2025-1005 ElementsKit Elementor addons <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor CWE-79 6.4 Medium 2025-02-15
CVE-2023-50903 WordPress Metform Elementor Contact Form Builder plugin <= 3.4.0 - Broken Access Control vulnerability — Metform CWE-862 5.3 Medium 2024-12-09
CVE-2024-37255 WordPress ElementsKit Lite plugin <= 3.1.4 - Unauthenticated Broken Access Control vulnerability — ElementsKit Elementor addons Lite CWE-862 5.3 Medium 2024-11-01
CVE-2024-9501 Wp Social Login and Register Social Counter <= 3.0.7 - Authentication Bypass via WordPress.com OAuth provider — Wp Social Login and Register Social Counter CWE-288 9.8 Critical 2024-10-26
CVE-2024-10091 ElementsKit Elementor addons <= 3.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor CWE-79 6.4 Medium 2024-10-26
CVE-2024-8546 ElementsKit Elementor addons <= 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor CWE-79 6.4 Medium 2024-09-25
CVE-2023-0714 Metform Elementor Contact Form Builder <= 3.2.4 - Unauthenticated Double-Extension Arbitrary File Upload — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor CWE-434 8.1 High 2024-08-17
CVE-2024-6698 FundEngine – Donation and Crowdfunding Platform <= 1.7.0 - Authenticated (Subscriber+) Privilege Escalation — FundEngine – Donation and Crowdfunding Platform CWE-862 8.8 High 2024-08-01
CVE-2024-6455 ElementsKit Elementor addons <= 3.2.0 - Unauthenticated Information Exposure via ekit_widgetarea_content Function — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor CWE-200 5.3 Medium 2024-07-18
CVE-2024-4266 MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 3.8.8 - Unauthenticated Sensitive Information Exposure — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor CWE-200 5.3 Medium 2024-06-11
CVE-2024-21746 WordPress Wp Ultimate Review plugin <= 2.3.6 - IP limit Bypass vulnerability — Wp Ultimate Review CWE-290 5.3 Medium 2024-05-17
CVE-2024-33570 WordPress MetForm plugin <= 3.8.3 - Broken Access Control vulnerability — Metform CWE-862 4.3 Medium 2024-05-06
CVE-2024-3499 ElementsKit Elementor addons <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Onepage Scroll Module — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor CWE-98 8.8 High 2024-05-02
CVE-2024-32505 WordPress ElementsKit Elementor addons plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability — ElementsKit Elementor addons Lite CWE-79 6.5 Medium 2024-04-17
CVE-2024-2803 ElementsKit Elementor addons <= 3.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor CWE-79 6.4 Medium 2024-04-04
CVE-2024-2791 Metform Elementor Contact Form Builder <= 3.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widgets — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor CWE-79 6.4 Medium 2024-04-02
CVE-2024-1238 ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor CWE-79 6.4 Medium 2024-03-30
CVE-2024-2047 ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Local File Inclusion in render_raw — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor CWE-98 8.8 High 2024-03-30
CVE-2024-2042 ElementsKit Elementor addons <= 3.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor CWE-79 6.4 Medium 2024-03-16

This page lists every published CVE security advisory associated with roxnor. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.