← back
CVE-2022-1170CWE-79

JobMonster < 4.5.2.9 - Unauthenticated Reflected Cross-Site Scripting

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 1.8%
exploitation probability
1.8%top 23% of all CVEs
observed exploitation
nono source reports it
In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.
Affected products
Unknown · Noo JobMonster