Nootheme develops a small portfolio of WordPress-based business and recruitment plugins, including JobMonster and Noo Timetable, that extend functionality for website administrators and end users. The vendor's vulnerability signal centers on application-layer input-handling and access-control issues, particularly cross-site scripting, cross-site request forgery, and path traversal weaknesses characteristic of web plugins. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nootheme over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57368HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Job | Jul 13, 2026 | 7.1 | 32 | NO | NO |
CVE-2025-54738CRITICAL Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster noo-jobmonster allows Authentication Abuse.This issue affects Jobmonster: from n/a thr | Aug 28, 2025 | 9.8 | 31 | NO | NO |
CVE-2022-1170MEDIUM In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests. | Apr 4, 2022 | 6.1 | 31 | NO | YES |
CVE-2025-67522CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NooTheme Jobmonster noo-jobmonster allows PHP Local File In | Dec 9, 2025 | 9.8 | 29 | NO | NO |
CVE-2026-25340CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonster noo-jobmonster allows Blind SQL Injection.This issue affec | Mar 25, 2026 | 9.3 | 28 | NO | NO |
CVE-2024-37927CRITICAL Incorrect Privilege Assignment vulnerability in NooTheme Jobmonster noo-jobmonster allows Privilege Escalation.This issue affects Jobmonster: from n/a through <= 4.7.5. | Jul 12, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-37928HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NooTheme Jobmonster allows File Manipulation.This issue affects Jobmonster: from n/a | Jul 12, 2024 | 8.6 | 25 | NO | NO |
CVE-2022-45828HIGH Cross-Site Request Forgery (CSRF) vulnerability in NooTheme Noo Timetable plugin <= 2.1.3 versions. | Jul 18, 2023 | 8.8 | 24 | NO | NO |
CVE-2025-54737HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Job | Nov 6, 2025 | 7.1 | 23 | NO | NO |
CVE-2025-53201HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Job | Aug 20, 2025 | 7.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nootheme.
Media articles that mention a CVE ID that affects a product developed by Nootheme — matched by CVE ID, not by vendor name.