Roxnor
18 CVEs tracked since 2023. Since Jun 2023, none of them reached CISA KEV.
Roxnor CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2023-06 | 11 | 0 |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | null or fewer | |
| 2023-12 | null or fewer | |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | 7 | 0 |
Products
The products that kept showing up in Roxnor's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Roxnor.
- CVE-2026-94500WordPress ElementsKit Elementor addons Lite plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2026-92235WP Ultimate Review <= 2.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter8.1
- CVE-2026-85575The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets <= 4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'shopengine_product_title_header_size' Parameter6.4
- CVE-2026-75971ShopEngine Elementor WooCommerce Builder Addon <= 4.9.4 - Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes7.2
- CVE-2026-18100MetForm <= 4.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mf_form_id' Widget Setting6.4
- CVE-2026-76063FundEngine <= 1.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wfp_featured_video_url' Parameter6.4
- CVE-2026-75930FundEngine <= 1.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'campaign_post' Parameter4.3
- CVE-2026-73993WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability9.8
- CVE-2026-32470WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability9.8
- CVE-2026-65440WordPress GetGenie plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-59560WordPress FundEngine plugin <= 1.7.8 - Broken Access Control vulnerability6.5
- CVE-2026-57406WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability6.5
- CVE-2026-57316WordPress GetGenie plugin <= 4.4.2 - Sensitive Data Exposure vulnerability6.5
- CVE-2026-4362ElementsKit Elementor Addons <= 3.8.2 - Missing Authorization to Unauthenticated Widget Content Overwrite6.5
- CVE-2026-5957EmailKit <= 1.6.5 - Authenticated (Author+) Arbitrary File Read via 'emailkit-editor-template' REST Parameter6.5
The record
- Peak rank
- #63 in Jun 2023
- Busiest month shown
- Jun 2023, 11 CVEs
- Months with a KEV entry
- 0 since Jun 2023
- Monthly snapshots
- 2 since 2023