Code-Projects Online Job Search Engine vulnerabilities

4 known vulnerabilities affecting code-projects/online_job_search_engine.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2025-12928MEDIUMCVSS 6.9v1.02025-11-10
CVE-2025-12928 [MEDIUM] CWE-74 CVE-2025-12928: A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument username/phone results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
cvelistv5nvd
CVE-2025-11583MEDIUMCVSS 6.9v1.02025-10-10
CVE-2025-11583 [MEDIUM] CWE-74 CVE-2025-11583: A flaw has been found in code-projects Online Job Search Engine 1.0. Impacted is an unknown function A flaw has been found in code-projects Online Job Search Engine 1.0. Impacted is an unknown function of the file /postjob.php. Executing manipulation of the argument txtjobID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
cvelistv5nvd
CVE-2025-11584MEDIUMCVSS 6.9v1.02025-10-10
CVE-2025-11584 [MEDIUM] CWE-74 CVE-2025-11584: A vulnerability has been found in code-projects Online Job Search Engine 1.0. The affected element i A vulnerability has been found in code-projects Online Job Search Engine 1.0. The affected element is an unknown function of the file /searchjob.php. The manipulation of the argument txtspecialization leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2025-11582MEDIUMCVSS 6.9v1.02025-10-10
CVE-2025-11582 [MEDIUM] CWE-74 CVE-2025-11582: A vulnerability was detected in code-projects Online Job Search Engine 1.0. This issue affects some A vulnerability was detected in code-projects Online Job Search Engine 1.0. This issue affects some unknown processing of the file /registration.php. Performing manipulation of the argument txtusername results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
cvelistv5nvd