CVE-2025-0369

Jet Engine <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parameter

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘list_tag’ parameter in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 35,310 live websites that are affected by CVE-2025-0369.

Run a Free Instant Scan




Affected Software

Product  Crocoblock JetEngine
Category Wordpress Plugins
Vulnerable Domains35,310 live websites (41% of Crocoblock JetEngine install base)
Vulnerable Versions
  • from 0 through 3.6.2
Vulnerable Versions Count149 versions ( 87% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jan 18, 2025
  • Updated - Jan 21, 2025

Credits

  • Matthew Rollings (finder)

Website Distribution by Country

Number of websites using CVE-2025-0369
United States7,727 websites



Brazil3,792 websites
Germany2,502 websites
Spain1,656 websites
France1,509 websites
Israel1,336 websites
GB1,332 websites
Iran1,274 websites
Netherlands1,256 websites
Italy1,115 websites

Website Distribution by TLD

Number of websites using CVE-2025-0369
.com12,579 websites
.com.br3,443 websites
.de1,219 websites
.org1,173 websites
.nl1,133 websites
.it843 websites
.co.uk768 websites
.ru753 websites
.es695 websites
.fr550 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-0369

Top websites that are affected by CVE-2025-0369. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******************.com United States**,***
******.com United States**,***
*************.com United States**,***
*****************.net GB**,***
*********.com United States**,***
**********.com United States**,***
***********.io United States**,***
*********.**.il United States**,***
******************.com United States**,***
***********.cl Chile**,***
See full domain list

FAQ

CVE-2025-0369 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crocoblock JetEngine
A total of 35,310 websites have been identified as vulnerable to CVE-2025-0369, based on global website indexing conducted by WebTechSurvey.
The Crocoblock JetEngine is affected by the CVE-2025-0369 vulnerability.
Crocoblock JetEngine versions up to and including 3.6.2 are vulnerable to CVE-2025-0369.