Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2022-25611

Disclosure Date: March 23, 2022 (last updated October 07, 2023)
Authenticated Stored Cross-Site Scripting (XSS) in Simple Event Planner plugin <= 1.5.4 allows attackers with contributor or higher user roles to inject the malicious script by using vulnerable parameter &custom[add_seg][].
Attacker Value
Unknown

CVE-2022-25612

Disclosure Date: March 23, 2022 (last updated October 07, 2023)
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in Simple Event Planner WordPress plugin <= 1.5.4 allows user with author or higher user rights inject the malicious code via vulnerable parameters: &custom[event_organiser], &custom[organiser_email], &custom[organiser_contact].
Attacker Value
Unknown

CVE-2021-39328

Disclosure Date: October 21, 2021 (last updated February 23, 2025)
The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $job_board_privacy_policy_label variable echo'd out via the ~/admin/settings/class-simple-job-board-settings-privacy.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 2.9.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
Attacker Value
Unknown

CVE-2020-35749

Disclosure Date: January 15, 2021 (last updated February 22, 2025)
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress allows remote attackers to read arbitrary files via the sjb_file parameter to wp-admin/post.php.
Attacker Value
Unknown

CVE-2017-18498

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The simple-job-board plugin before 2.4.4 for WordPress has reflected XSS via keyword search.
0