Wpjobboard is a niche WordPress-based job board plugin ecosystem represented by products such as Wpjobboard and Jobeleon, with vulnerabilities centering on classic web application input-handling flaws. The recurring exposure involves cross-site scripting and SQL injection weaknesses, typical of content-management and form-processing plugins where user input flows directly into page rendering and database queries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpjobboard over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36525HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPJobBoard allows Blind SQL Injection.This issue affects WPJobBoard: from n/a | Dec 24, 2025 | 8.6 | 28 | NO | NO |
CVE-2018-5695HIGH The WpJobBoard plugin 4.4.4 for WordPress allows SQL injection via the order or sort parameter to the wpjb-job or wpjb-alerts module, with a request to wp-admin/admin.php. | Jan 14, 2018 | 7.2 | 22 | NO | NO |
CVE-2020-9019MEDIUM The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Description. | Feb 25, 2020 | 6.1 | 21 | NO | NO |
CVE-2017-15375MEDIUM Multiple client-side cross site scripting vulnerabilities have been discovered in the WpJobBoard v4.5.1 web-application for WordPress. The vulnerabilities are located in the `query | Oct 16, 2017 | 6.1 | 21 | NO | NO |
CVE-2022-47153MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPJobBoard Jobeleon Theme allows Reflected XSS.This issue affects Jobeleon The | Mar 29, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpjobboard.
Media articles that mention a CVE ID that affects a product developed by Wpjobboard — matched by CVE ID, not by vendor name.