Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

jetmonsters — Vulnerabilities & Security Advisories 55

Browse all 55 CVE security advisories affecting jetmonsters. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Jetmonsters operates as a software development entity, primarily focusing on creating digital assets and applications for the gaming and entertainment sectors. Security audits have identified thirty-five distinct Common Vulnerabilities and Exposures (CVEs) associated with its products, highlighting significant historical weaknesses in code quality and implementation. The most prevalent vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, which often stem from insufficient input validation and improper access controls. These defects have occasionally allowed attackers to compromise system integrity or access sensitive user data without authorization. While no single catastrophic incident has defined the company’s public record, the cumulative volume of disclosed CVEs suggests a pattern of recurring security oversights. This trend underscores the necessity for rigorous static analysis and continuous integration security testing to mitigate risks before deployment.

CVE ID Title CVSS Severity Published
CVE-2025-54038 WordPress Restaurant Menu by MotoPress plugin <= 2.4.6 - Cross Site Request Forgery (CSRF) Vulnerability — Restaurant Menu by MotoPress CWE-352 5.4 Medium 2025-07-16
CVE-2025-53990 WordPress JetFormBuilder plugin <= 3.5.1.2 - PHP Object Injection Vulnerability — JetFormBuilder CWE-502 7.2 High 2025-07-16
CVE-2025-48258 WordPress Mega Menu Block plugin <= 1.0.6 - Cross Site Scripting (XSS) Vulnerability — Mega Menu Block CWE-79 6.5 Medium 2025-05-19
CVE-2025-30846 WordPress Restaurant Menu by MotoPress plugin <= 2.4.4 - Local File Inclusion vulnerability — Restaurant Menu by MotoPress CWE-98 8.8 High 2025-03-27
CVE-2024-13642 Stratum – Elementor Widgets <= 1.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting Vulnerability via Image Hotspot Widget — Stratum Widgets for Elementor CWE-79 6.4 Medium 2025-01-30
CVE-2024-10316 Stratum – Elementor Widgets <= 1.4.4 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates — Stratum Widgets for Elementor CWE-200 4.3 Medium 2024-11-21
CVE-2024-10872 Getwid – Gutenberg Blocks <= 2.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting — Getwid – Gutenberg Blocks CWE-79 6.4 Medium 2024-11-20
CVE-2024-10323 JetWidgets For Elementor <= 1.0.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload — JetWidgets For Elementor CWE-79 6.4 Medium 2024-11-12
CVE-2020-36840 Timetable and Event Schedule by MotoPress <= 2.3.8 - Missing Authorization — Timetable and Event Schedule by MotoPress CWE-862 7.3 High 2024-10-16
CVE-2024-7291 JetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege Escalation — JetFormBuilder — Dynamic Blocks Form Builder CWE-269 7.2 High 2024-08-03
CVE-2024-6489 Getwid – Gutenberg Blocks <= 2.0.10 - Missing Authorization to Google API key update — Getwid – Gutenberg Blocks CWE-862 5.3 Medium 2024-07-20
CVE-2024-6491 Getwid – Gutenberg Blocks <= 2.0.10 - Missing Authentication to MailChimp API key update — Getwid – Gutenberg Blocks CWE-862 4.3 Medium 2024-07-20
CVE-2024-4626 JetWidgets For Elementor <= 1.0.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_type and id Parameters — JetWidgets For Elementor CWE-79 6.4 Medium 2024-06-20
CVE-2024-5611 Stratum – Elementor Widgets <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget — Stratum Widgets for Elementor CWE-79 6.4 Medium 2024-06-15
CVE-2024-4413 Hotel Booking Lite <= 4.11.1 - Unauthenticated PHP Object Injection — MotoPress Hotel Booking CWE-502 9.8 Critical 2024-05-10
CVE-2024-3588 Getwid – Gutenberg Blocks <= 2.0.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'Countdown' — Getwid – Gutenberg Blocks CWE-79 6.4 Medium 2024-05-02
CVE-2024-3342 Timetable and Event Schedule by MotoPress <= 2.4.11 - Authenticated (Contributor+) SQL Injection — Timetable and Event Schedule by MotoPress CWE-89 9.9 Critical 2024-04-27
CVE-2024-2138 JetWidgets For Elementor <= 1.0.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box Widget — JetWidgets For Elementor CWE-79 6.4 Medium 2024-04-09
CVE-2024-2507 JetWidgets For Elementor <= 1.0.16 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Button URL — JetWidgets For Elementor CWE-79 6.4 Medium 2024-04-09
CVE-2024-1948 Getwid – Gutenberg Blocks <= 2.0.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via Block Content — Getwid – Gutenberg Blocks CWE-79 6.4 Medium 2024-04-09
CVE-2023-6963 Getwid – Gutenberg Blocks <= 2.0.4 - Captcha Bypass — Getwid – Gutenberg Blocks CWE-804 5.3 Medium 2024-02-05
CVE-2023-6959 Getwid – Gutenberg Blocks <= 2.0.4 - Missing Authorization to Recaptcha API Key Modification — Getwid – Gutenberg Blocks CWE-862 4.3 Medium 2024-02-05
CVE-2023-1895 Getwid – Gutenberg Blocks <= 1.8.3 - Authenticated(Subscriber+) Server Side Request Forgery — Getwid – Gutenberg Blocks CWE-918 8.5 High 2023-06-09
CVE-2023-1910 Getwid – Gutenberg Blocks <= 1.8.3 - Improper Authorization via get_remote_templates REST endpoint — Getwid – Gutenberg Blocks CWE-285 4.3 Medium 2023-06-09
CVE-2023-0086 JetWidgets for Elementor <= 1.0.12 - Cross-Site Request Forgery to Settings Update — JetWidgets For Elementor CWE-352 5.4 Medium 2023-01-05

This page lists every published CVE security advisory associated with jetmonsters. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.