Medium 6.5
2025-11-06< 6.0.5
CVE-2025-58986
Minimum safe version
6.0.5
Update to 6.0.5 or later to address 7 fixable vulnerabilities
CVE-2025-58986
Jock on air now < 5.6.3 - Authenticated Stored Cross-Site Scripting
Jock on air now < 5.6.2 - Reflected Cross-Site Scripting
Jock on air now < 5.6.2 - Arbitrary Plugin's Settings Update via CSRF
Jock on air now <= 5.6.1 - Reflected Cross-Site Scripting
Jock on air now <= 5.6.2 - Unauthenticated Stored Cross-Site Scripting
Jock on air now <= 5.6.1 - Cross-Site Request Forgery to Settings Update