CVE-2025-67522
- EPSS 0.17%
- Veröffentlicht 09.12.2025 14:13:59
- Zuletzt bearbeitet 20.01.2026 15:19:16
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NooTheme Jobmonster noo-jobmonster allows PHP Local File Inclusion.This issue affects Jobmonster: from n/a through <= 4.8.2.
CVE-2025-54737
- EPSS 0.05%
- Veröffentlicht 06.11.2025 15:54:17
- Zuletzt bearbeitet 20.01.2026 15:17:01
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through <= 4.7.8.
CVE-2025-54738
- EPSS 0.08%
- Veröffentlicht 28.08.2025 12:37:39
- Zuletzt bearbeitet 29.08.2025 16:24:29
Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster allows Authentication Abuse. This issue affects Jobmonster: from n/a through 4.7.9.
CVE-2025-57887
- EPSS 0.03%
- Veröffentlicht 22.08.2025 12:15:32
- Zuletzt bearbeitet 22.08.2025 18:08:51
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster allows Stored XSS. This issue affects Jobmonster: from n/a through 4.8.0.
CVE-2025-57888
- EPSS 0.04%
- Veröffentlicht 22.08.2025 12:15:32
- Zuletzt bearbeitet 22.08.2025 18:08:51
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NooTheme Jobmonster allows Retrieve Embedded Sensitive Data. This issue affects Jobmonster: from n/a through 4.8.0.
CVE-2025-53201
- EPSS 0.03%
- Veröffentlicht 20.08.2025 08:03:20
- Zuletzt bearbeitet 20.08.2025 14:39:07
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster allows Reflected XSS. This issue affects Jobmonster: from n/a through 4.7.8.
CVE-2024-37927
- EPSS 0.71%
- Veröffentlicht 12.07.2024 14:15:13
- Zuletzt bearbeitet 21.11.2024 09:24:31
Improper Privilege Management vulnerability in NooTheme Jobmonster allows Privilege Escalation.This issue affects Jobmonster: from n/a through 4.7.0.
CVE-2024-37928
- EPSS 0.65%
- Veröffentlicht 12.07.2024 14:15:13
- Zuletzt bearbeitet 21.11.2024 09:24:31
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NooTheme Jobmonster allows File Manipulation.This issue affects Jobmonster: from n/a through 4.7.0.
CVE-2022-1170
- EPSS 0.93%
- Veröffentlicht 04.04.2022 16:15:11
- Zuletzt bearbeitet 21.11.2024 06:40:10
In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.
CVE-2022-1166
- EPSS 0.34%
- Veröffentlicht 04.04.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:40:10
The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file. This could expose personal data such as people's resumes. Although Directory Listing ...