CVE Tools

Roxnor

18 CVEs tracked since 2023. Since Jun 2023, none of them reached CISA KEV.

Roxnor CVEs per month

Jun 2023 to Mar 2024. Point at a month, or focus the strip and use the arrow keys.
Roxnor CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-06110
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-0370

Products

The products that kept showing up in Roxnor's monthly top three, with their CVEs summed over those months.

  1. Metform – Contact Form, Survey, Quiz, & Custom Form Builder For Elementor122 months
  2. Elementskit Elementor Addons – Advanced Widgets & Templates Addons For Elementor51 month
  3. Wp Social Login and Register Social Counter11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Roxnor.

  1. CVE-2026-94500WordPress ElementsKit Elementor addons Lite plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability6.5
  2. CVE-2026-92235WP Ultimate Review <= 2.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter8.1
  3. CVE-2026-85575The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets <= 4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'shopengine_product_title_header_size' Parameter6.4
  4. CVE-2026-75971ShopEngine Elementor WooCommerce Builder Addon <= 4.9.4 - Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes7.2
  5. CVE-2026-18100MetForm <= 4.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mf_form_id' Widget Setting6.4
  6. CVE-2026-76063FundEngine <= 1.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wfp_featured_video_url' Parameter6.4
  7. CVE-2026-75930FundEngine <= 1.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'campaign_post' Parameter4.3
  8. CVE-2026-73993WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability9.8
  9. CVE-2026-32470WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability9.8
  10. CVE-2026-65440WordPress GetGenie plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability7.1
  11. CVE-2026-59560WordPress FundEngine plugin <= 1.7.8 - Broken Access Control vulnerability6.5
  12. CVE-2026-57406WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability6.5
  13. CVE-2026-57316WordPress GetGenie plugin <= 4.4.2 - Sensitive Data Exposure vulnerability6.5
  14. CVE-2026-4362ElementsKit Elementor Addons <= 3.8.2 - Missing Authorization to Unauthenticated Widget Content Overwrite6.5
  15. CVE-2026-5957EmailKit <= 1.6.5 - Authenticated (Author+) Arbitrary File Read via 'emailkit-editor-template' REST Parameter6.5

The record

Peak rank
#63 in Jun 2023
Busiest month shown
Jun 2023, 11 CVEs
Months with a KEV entry
0 since Jun 2023
Monthly snapshots
2 since 2023
Roxnor's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store