Thème WordPress
Vulnérabilités Careerfy – Job Board WordPress Theme
Cette page rassemble les failles publiées pour Careerfy – Job Board WordPress Theme, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Careerfy – Job Board WordPress Theme
9 fiches
Careerfy <= 7.0 – Cross-Site Request Forgery and Missing Authorization
The Careerfy theme for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, and including, 7.0. This is due to missing nonce validation and capability checks on several functions. This makes it possible…
*-7.0
7.1.0
24/09/2021
Careerfy <= 4.3.0 – Reflected Cross-Site Scripting
The Careerfy for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute…
[*, 4.4.0)
4.4.0
22/07/2020
Careerfy <= 4.2.0 – Reflected Cross-Site Scripting
The Careerfy theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-4.2.0
4.3.0
18/07/2020
Careerfy <= 4.0.0 – Cross-Site Scripting
The Careerfy theme for WordPress is vulnerable to Multiple Cross-Site Scripting in versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-4.0.0
4.1.0
05/07/2020
Careerfy – Job Board WordPress Theme <= 3.9.0 – Reflected Cross-Site Scripting
The Careerfy – Job Board WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘location’ parameter in versions up to, and including, 3.9.0 due to insufficient input sanitization and output escaping. This makes it…
*-3.9.0
4.0.0
01/07/2020
Careerfy – Job Board WordPress Theme <= 3.9.0 – Authenticated Stored Cross-Site Scripting
The Careerfy – Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Academic Level', 'Age', 'Salary', 'Gender', 'Industry', and 'Full Address' fields in versions up to, and including, 3.9.0 due to insufficient…
*-3.9.0
4.0.0
01/07/2020
Careerfy – Job Board WordPress Theme <= 3.9.0 – Authenticated Stored Cross-Site Scripting
The Careerfy – Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Member Title', 'Designation', 'Experience', 'Facebook URL', 'Google+ URL', 'Twitter URL', 'LinkedIn URL', 'Description', and 'Full Address' fields in versions up…
*-3.9.0
4.0.0
01/07/2020
Careerfy – Job Board WordPress Theme <= 3.9.0 – Authenticated Stored Cross-Site Scripting
The Careerfy – Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Career Level', 'Experience', 'Gender', 'Industry', 'Qualifications', 'Job Description', and 'Full Address' fields in versions up to, and including, 3.9.0 due…
*-3.9.0
4.0.0
01/07/2020
Careerfy < 3.9.0 – Cross-Site Scripting
The Careerfy theme plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in…
[*, 3.9.0)
3.9.0
03/06/2020
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.