CVE-2026-97265: Crocoblock. Jetimpex Inc Jetengine

Medium severity, CVSS 6.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3.

Affected products

Published 2026-09-30. Last modified 2026-09-30.