Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.25% | — | Nokri JOB BoardAI | 5/9/2026 | 8/9/2026 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Media (5.9) | 0.32% | — | Themeglow Jobboard JOB ListingAIThemeglow Job-board-lightAI | 20/2/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in themeglow JobBoard Job listing job-board-light allows Retrieve Embedded Sensitive Data.This issue affects JobBoard Job listing: from n/a through <= 1.2.8. | |
| Aplazada | Media (5.9) | 0.21% | — | Brownbagmarketing Greenhouse JOB BoardAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brownbagmarketing Greenhouse Job Board greenhouse-job-board allows DOM-Based XSS.This issue affects Greenhouse Job Board: from n/a through <= 2.7.3. | |
| Aplazada | Media (6.1) | 0.26% | — | Bestwebsoft JOB BoardAI | 25/11/2025 | 17/6/2026 | The Job Board by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2.1. This is due to the plugin storing the entire unsanitized `$_GET` superglobal array directly into the database via `update_user_meta()` when users save search results, and later… | |
| Aplazada | Alta (7.5) | 0.39% | — | Presstigers Simple JOB BoardAI | 22/10/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in PressTigers Simple Job Board simple-job-board allows Retrieve Embedded Sensitive Data.This issue affects Simple Job Board: from n/a through <= 2.13.7. | |
| Aplazada | Media (6.5) | 0.22% | — | Pickplugins JOB Board ManagerAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager job-board-manager allows DOM-Based XSS.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Aplazada | Baja (3.8) | 0.25% | — | Pickplugins JOB Board ManagerAI | 5/9/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Aplazada | Alta (8.8) | 0.18% | — | Dexignzone Jobzilla - JOB Board Wordpress ThemeAI | 20/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DexignZone JobZilla - Job Board WordPress Theme jobzilla allows Privilege Escalation.This issue affects JobZilla - Job Board WordPress Theme: from n/a through <= 2.0. | |
| Aplazada | Media (5.3) | 0.32% | — | Pickplugins JOB Board ManagerAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through <= 2.1.60. | |
| Analizada | Baja (3.7) | 0.40% | — | Presstigers Simple JOB Board | 15/5/2025 | 17/6/2026 | The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthenticated users to access and download uploaded resumes | |
| Analizada | Media (6.1) | 0.36% | — | Presstigers Simple JOB Board | 15/5/2025 | 17/6/2026 | In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor | |
| Aplazada | Alta (8.1) | 0.51% | — | Eyecix Jobsearch WP JOB BoardAI | 25/4/2025 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.8) | 1.0% | — | Pickplugins JOB Board ManagerAI | 11/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PickPlugins Job Board Manager job-board-manager allows Object Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Aplazada | Media (5.3) | 0.34% | — | Pickplugins JOB Board ManagerAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Aplazada | Media (4.9) | 0.56% | — | Themeglow JOB Board LightAI | 1/4/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in themeglow JobBoard Job listing job-board-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoard Job listing: from n/a through <= 1.2.8. | |
| Aplazada | Alta (7.1) | 0.32% | — | Pickplugins JOB Board ManagerAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager job-board-manager allows Reflected XSS.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Aplazada | Media (5.4) | 0.19% | — | Pickplugins JOB Board ManagerAI | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Job Board Manager job-board-manager allows Cross Site Request Forgery.This issue affects Job Board Manager: from n/a through <= 2.1.59. | |
| Aplazada | Crítica (10) | 0.53% | — | Themeglow Job-board-lightAI | 7/1/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in themeglow JobBoard Job listing job-board-light allows Upload a Web Shell to a Web Server.This issue affects JobBoard Job listing: from n/a through <= 1.2.6. | |
| Modificada | Crítica (9.8) | 0.44% | — | Presstigers Simple JOB Board | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in PressTigers Simple Job Board simple-job-board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Job Board: from n/a through <= 2.10.5. | |
| Aplazada | Media (5.3) | 0.55% | — | Pickplugins JOB Board ManagerAI | 16/12/2024 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Aplazada | Crítica (9.8) | 0.65% | — | Eyecix Jobsearch WP JOB BoardAI | 28/11/2024 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible for unauthenticated… | |
| Analizada | Crítica (9.8) | 0.86% | — | Eyecix Jobsearch WP JOB Board | 6/11/2024 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the… | |
| Analizada | Alta (8.8) | 0.79% | — | Eyecix Jobsearch WP JOB Board | 6/11/2024 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload… | |
| Analizada | Crítica (9.8) | 0.43% | — | Eyecix Jobsearch WP JOB Board | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in eyecix JobSearch allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JobSearch: from n/a through 2.5.4. | |
| Analizada | Alta (8.8) | 0.38% | — | Eyecix Jobsearch WP JOB Board | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through 2.5.4. |