CVE Tools

Jetmonsters

10 CVEs tracked since 2024. Since Apr 2024, none of them reached CISA KEV.

Jetmonsters CVEs per month

Apr 2024 to Dec 2025. Point at a month, or focus the strip and use the arrow keys.
Jetmonsters CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-0450
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-1250

Products

The products that kept showing up in Jetmonsters's monthly top three, with their CVEs summed over those months.

  1. Jetwidgets For Elementor21 month
  2. Emmet Lite11 month
  3. Getwid – Gutenberg Blocks11 month
  4. Hotel Booking Lite11 month
  5. Restaurant Menu By Motopress11 month
  6. Stratum11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Jetmonsters.

  1. CVE-2026-96568Restaurant Menu and Food Ordering <= 2.4.14 - Unauthenticated Stored Cross-Site Scripting via 'phone_number' Parameter7.2
  2. CVE-2026-92212JetFormBuilder <= 3.6.5.3 - Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field6.1
  3. CVE-2026-5924Getwid <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps 'customStyle'6.4
  4. CVE-2026-12793JetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter9.8
  5. CVE-2026-90650MotoPress Hotel Booking <= 6.2.4 - Unauthenticated Stored Cross-Site Scripting via Stripe Webhook Event Object 'id'7.2
  6. CVE-2026-73400WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Local File Inclusion vulnerability8.1
  7. CVE-2026-28140WordPress JetFormBuilder plugin <= 3.6.4.1 - Broken Access Control vulnerability7.5
  8. CVE-2026-9180MotoPress Appointment Booking <= 2.4.4 - Unauthenticated Insecure Direct Object Reference to 'payment_details.booking_id' Parameter5.3
  9. CVE-2026-57347WordPress Hotel Booking Lite plugin <= 6.0.3 - Sensitive Data Exposure vulnerability6.5
  10. CVE-2026-13459JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter5.3
  11. CVE-2026-13454MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter6.5
  12. CVE-2026-11380JetWidgets For Elementor <= 1.0.21 - Authenticated (Author+) Stored Cross-Site Scripting via Animated Box 'animation_effect' Setting6.4
  13. CVE-2026-57644WordPress Restaurant Menu by MotoPress plugin <= 2.4.10 - SQL Injection vulnerability8.5
  14. CVE-2025-63078WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Broken Access Control vulnerability4.3
  15. CVE-2026-54196WordPress JetFormBuilder plugin <= 3.6.1 - Privilege Escalation vulnerability6.8

The record

Peak rank
#170 in Apr 2024
Busiest month shown
Apr 2024, 5 CVEs
Months with a KEV entry
0 since Apr 2024
Monthly snapshots
2 since 2024
Jetmonsters's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store