VYPR

Js Jobs

by Joomsky

CVEs (7)

  • CVE-2018-5994CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in a view_resume request.

  • CVE-2019-17527CriDec 19, 2019
    risk 0.64cvss 9.8epss 0.01

    dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Injection via the index.php?option=com_jsjobs&task=customfields.getfieldtitlebyfieldandfieldfo child parameter.

  • CVE-2020-37226HigMay 13, 2026
    risk 0.46cvss 7.1epss 0.00

    Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby'…

  • CVE-2018-9183MedApr 2, 2018
    risk 0.38cvss 5.4epss 0.02

    The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS.

  • CVE-2025-22209MedFeb 15, 2025
    risk 0.31cvss 4.7epss 0.00

    A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' parameter in the Employer Payment History search feature.

  • CVE-2025-22208MedFeb 15, 2025
    risk 0.31cvss 4.7epss 0.01

    A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' parameter in the GDPR Erase Data Request search feature.

  • CVE-2025-22206MedFeb 4, 2025
    risk 0.31cvss 4.7epss 0.09

    A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature.