Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.32% | — | Themeglow Jobboard JOB ListingAIThemeglow Job-board-lightAI | 20/2/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in themeglow JobBoard Job listing job-board-light allows Retrieve Embedded Sensitive Data.This issue affects JobBoard Job listing: from n/a through <= 1.2.8. | |
| Aplazada | Alta (8.6) | 0.48% | — | WpjobboardAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPJobBoard allows Blind SQL Injection.This issue affects WPJobBoard: from n/a through 5.9.0. | |
| Aplazada | Crítica (9.3) | 0.43% | — | Clickandpledge Click Pledge WpjobboardAI | 10/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge WordPress-WPJobBoard click-pledge-wpjobboard allows Blind SQL Injection.This issue affects WordPress-WPJobBoard: from n/a through <= 25.07010000-WP6.8.1-JB5.11.5. | |
| Aplazada | Crítica (9.6) | 0.24% | — | WpjobboardAI | 15/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This issue affects WPJobBoard: from n/a through n/a. | |
| Aplazada | Media (5.4) | 0.32% | — | WpjobboardAI | 15/4/2025 | 17/6/2026 | Path Traversal vulnerability in NotFound WPJobBoard allows Path Traversal. This issue affects WPJobBoard: from n/a through n/a. | |
| Aplazada | Media (4.3) | 0.15% | — | WpjobboardAI | 15/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue affects WPJobBoard: from n/a through n/a. | |
| Aplazada | Media (5.3) | 0.47% | — | Themeglow JobboardAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in themeglow JobBoard Job listing job-board-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoard Job listing: from n/a through <= 1.2.8. | |
| Aplazada | Alta (7.1) | 0.31% | — | WpjobboardAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WPJobBoard allows Reflected XSS. This issue affects WPJobBoard: from n/a through 5.10.1. | |
| Modificada | Alta (8.8) | 0.55% | — | Ultimatemember Jobboardwp | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in JobBoardWP JobBoardWP – Job Board Listings and Submissions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoardWP – Job Board Listings and Submissions: from n/a through 1.2.2. | |
| Analizada | Media (6.1) | 0.47% | — | Ultimatemember Jobboardwp | 23/11/2024 | 17/6/2026 | The JobBoardWP – Job Board Listings and Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Media (6.1) | 0.37% | — | Wpjobboard Jobeleon | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPJobBoard Jobeleon Theme allows Reflected XSS.This issue affects Jobeleon Theme: from n/a through 1.9.1. | |
| Modificada | Alta (7.5) | 1.4% | — | Ultimatemember Jobboardwp | 19/12/2022 | 17/6/2026 | The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthenticated users to upload arbitrary files such as PHP. | |
| Modificada | Media (4.8) | 1.0% | — | Ultimatemember Jobboardwp | 19/10/2021 | 17/6/2026 | The JobBoardWP WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/includes/admin/class-metabox.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and… | |
| Modificada | Media (6.1) | 1.6% | — | Wpjobboard | 25/2/2020 | 17/6/2026 | The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Description. | |
| Modificada | Alta (7.2) | 1.2% | — | Wpjobboard | 14/1/2018 | 17/6/2026 | The WpJobBoard plugin 4.4.4 for WordPress allows SQL injection via the order or sort parameter to the wpjb-job or wpjb-alerts module, with a request to wp-admin/admin.php. | |
| Modificada | Media (6.1) | 0.90% | — | Wpjobboard | 16/10/2017 | 17/6/2026 | Multiple client-side cross site scripting vulnerabilities have been discovered in the WpJobBoard v4.5.1 web-application for WordPress. The vulnerabilities are located in the `query` and `id` parameters of the `wpjb-email`, `wpjb-job`, `wpjb-application`, and `wpjb-membership` modules. Remote attackers are able to… | |
| Modificada | Alta (7.5) | 1.8% | — | Phpjobboard | 15/2/2007 | 16/6/2026 | phpjobboard allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin.php with adminop=job-edit. |