N/A
2026-04-30< 3.8.8.2
JetEngine <= 3.8.8.1 - Unauthenticated SQL Injection
Minimum safe version
3.8.8.2
Update to 3.8.8.2 or later to address 20 fixable vulnerabilities
JetEngine <= 3.8.8.1 - Unauthenticated SQL Injection
JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via '_cct_search' Parameter
JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter
CVE-2026-32355
CVE-2026-28134
CVE-2025-68495
CVE-2025-67923
CVE-2025-69333
CVE-2025-49938
CVE-2025-53194
CVE-2025-54688
CVE-2025-53196
CVE-2025-53195
CVE-2025-26870
WordPress JetEngine Plugin <= 3.6.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-48757
CVE-2023-48758
CVE-2023-48761
CVE-2023-48762
WordPress JetEngine Plugin < 3.1.3.1 is vulnerable to Remote Code Execution (RCE)