Simplejobscript is a focused job-scheduling application whose vulnerability profile, while narrow in product scope, skews strongly toward critical-severity outcomes. The recurring exposure centers on application-layer input-handling and file-handling defects—SQL injection, cross-site scripting, and unrestricted file upload—that are characteristic of web-facing administrative tools with insufficient input validation and access controls. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simplejobscript over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8645CRITICAL An issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job applications search function. The vulnerable parameter is job | Feb 7, 2020 | 9.8 | 30 | NO | NO |
CVE-2019-25499CRITICAL Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the job_id parameter. A | Mar 4, 2026 | 9.8 | 29 | NO | NO |
CVE-2020-8440CRITICAL controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a resume. | Jan 31, 2020 | 9.8 | 29 | NO | NO |
CVE-2019-25501HIGH Simple Job Script contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code through the app_id parameter. Attacke | Mar 4, 2026 | 8.2 | 25 | NO | NO |
CVE-2019-25500HIGH Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the employerid paramete | Mar 4, 2026 | 8.2 | 25 | NO | NO |
CVE-2019-25498HIGH Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the landing_location pa | Mar 4, 2026 | 8.2 | 25 | NO | NO |
CVE-2020-7229CRITICAL An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landing_location. The function is cou | Jan 21, 2020 | 9.8 | 24 | NO | NO |
CVE-2019-25502MEDIUM Simple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the job_type_value parameter in th | Mar 4, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simplejobscript.
Media articles that mention a CVE ID that affects a product developed by Simplejobscript — matched by CVE ID, not by vendor name.