Vulnerabilities > Artbees > Jupiter X Core > 1.15.0

DATE CVE VULNERABILITY TITLE RISK
2025-02-01 CVE-2025-0365 Path Traversal vulnerability in Artbees Jupiter X Core
The Jupiter X Core plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.8.7 via the inline SVG feature.
network
low complexity
artbees CWE-22
6.5
2025-02-01 CVE-2025-0366 Unspecified vulnerability in Artbees Jupiter X Core
The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 via the get_svg() function.
network
low complexity
artbees
8.8
2025-01-07 CVE-2024-12033 Missing Authorization vulnerability in Artbees Jupiter X Core
The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sync_libraries() function in all versions up to, and including, 4.8.5.
network
low complexity
artbees CWE-862
4.3
2025-01-07 CVE-2024-12316 Missing Authorization vulnerability in Artbees Jupiter X Core
The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_popup_action() function in all versions up to, and including, 4.8.5.
network
low complexity
artbees CWE-862
5.3
2024-09-26 CVE-2024-7772 Unrestricted Upload of File with Dangerous Type vulnerability in Artbees Jupiter X Core
The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function in all versions up to, and including, 4.6.5.
network
low complexity
artbees CWE-434
critical
9.8
2024-09-26 CVE-2024-7781 Missing Authentication for Critical Function vulnerability in Artbees Jupiter X Core
The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5.
network
low complexity
artbees CWE-306
critical
9.8
2024-06-21 CVE-2023-38389 Unspecified vulnerability in Artbees Jupiter X Core
Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.
network
low complexity
artbees
critical
9.8
2024-03-26 CVE-2023-38388 Unspecified vulnerability in Artbees Jupiter X Core
Unrestricted Upload of File with Dangerous Type vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from n/a through 3.3.5.
network
low complexity
artbees
critical
9.8
2022-06-13 CVE-2022-1656 Unspecified vulnerability in Artbees Jupiter X Core and Jupiterx
Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to access any of the functions registered in lib/api/api/ajax.php, which also grant access to the jupiterx_api_ajax_ actions registered by the JupiterX Core Plugin (<=2.0.6).
network
low complexity
artbees
5.4