ZeroHour

CVE-2025-22209

PoC
CVSS 3.1
4.7 medium
EPSS
<1%p22
Published
()
Modified
Description

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' parameter in the Employer Payment History search feature.

Vendors
joomsky
Products
js jobs
Ecosystems
Joomla
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.