<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Joomla!</title>
  <link>https://cvedaily.com/pages/tags/joomla.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/joomla.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Joomla!</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:35 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2018-25433 – Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25433</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25433</strong></p>
  <p>Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted categoryid values in the com_jephotogallery component to execute arbitrary SQL queries and retrieve sensitive data like usernam…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25381 – Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25381</guid>
    <pubDate>Mon, 25 May 2026 15:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25381</strong></p>
  <p>Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers can inject malicious SQL code via the filter_type_id, filter_pid_id, and filter_search parameters in POST requests to extract sensitive database information including credentials and server details.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25380 – Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25380</guid>
    <pubDate>Mon, 25 May 2026 15:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25380</strong></p>
  <p>Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, and filter_search parameters. Attackers can submit POST requests to the extroformfield view with malicious SQL payloads to extract sensitive database information and server data.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25354 – Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25354</guid>
    <pubDate>Sat, 23 May 2026 19:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25354</strong></p>
  <p>Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authenticated users into visiting malicious pages. Attackers can craft HTML forms targeting the account/index endpoint with hidden fields to change passwords, email addresses, and profile details without user consent.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25351 – Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25351</guid>
    <pubDate>Sat, 23 May 2026 19:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25351</strong></p>
  <p>Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the username parameter. Attackers can submit POST requests to the login endpoint with SQL injection payloads in the username field to extract database information including user credentials and system details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25348 – Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25348</guid>
    <pubDate>Sat, 23 May 2026 19:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25348</strong></p>
  <p>Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send GET requests to the user_detail view with malicious cid values containing SQL commands to extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25337 – Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25337</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25337</guid>
    <pubDate>Sun, 17 May 2026 13:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25337</strong></p>
  <p>Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML forms targeting account endpoints like /joomoc2/?route=account/edit and to modify user information or reset passwords without user consent.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25337">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25330 – Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25330</guid>
    <pubDate>Sun, 17 May 2026 13:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25330</strong></p>
  <p>Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users visit the profile, or submit SQL injection payloads via the phone_no parameter to the user_setting…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25327 – Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25327</guid>
    <pubDate>Sun, 17 May 2026 13:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25327</strong></p>
  <p>Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete job entries or modify component settings when administrators visit attacker-controlled pages.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37226 – Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37226</guid>
    <pubDate>Wed, 13 May 2026 16:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37226</strong></p>
  <p>Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' values to extract sensitive database information using automated tools.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37224 – Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37224</guid>
    <pubDate>Wed, 13 May 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37224</strong></p>
  <p>Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' values to extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37219 – Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37219</guid>
    <pubDate>Wed, 13 May 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37219</strong></p>
  <p>Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET requests to the onAjax_files method with path traversal sequences to enumerate files in system directories outside the intended web root.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37218 – Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37218</guid>
    <pubDate>Wed, 13 May 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37218</strong></p>
  <p>Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hdwplayersearch parameter. Attackers can submit POST requests with crafted SQL payloads in the hdwplayersearch parameter to extract sensitive database information from the hdwplayer_videos table.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47930 – Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47930</guid>
    <pubDate>Sun, 10 May 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47930</strong></p>
  <p>Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in the 'id' field parameter to extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34424 – Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34424</guid>
    <pubDate>Thu, 09 Apr 2026 23:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34424</strong></p>
  <p>Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTTP headers, establish authenticated backdoors accepting arbitrary PHP code or OS commands, create hi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-506</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-54364 – Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-54364</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-54364</guid>
    <pubDate>Thu, 09 Apr 2026 21:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-54364</strong></p>
  <p>Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, from_task, or from_itemid parameters to steal session tokens or login credentials when victims visit t…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-54364">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-54363 – Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-54363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-54363</guid>
    <pubDate>Thu, 09 Apr 2026 21:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-54363</strong></p>
  <p>Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters including show, reviews, type_id, distance, facilities, categories, prices, location, and Itemid. Attackers can craft malicious URLs containing JavaScript payloads in these parameters to steal session tokens, login…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-54363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-54362 – Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-54362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-54362</guid>
    <pubDate>Thu, 09 Apr 2026 21:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-54362</strong></p>
  <p>Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft malicious URLs containing script payloads in the keyword parameter of the product-variants endpoint to execute arbitrary JavaScript in victim browsers and steal session tokens or credentials.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-54362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-54361 – Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-54361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-54361</guid>
    <pubDate>Thu, 09 Apr 2026 21:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-54361</strong></p>
  <p>Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can craft URLs containing JavaScript payloads in the filter_keyword GET parameter of the all-properties-with-map endpoint to execute arbitrary code in victim browsers and steal session tokens or credent…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-54361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-54360 – Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-54360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-54360</guid>
    <pubDate>Thu, 09 Apr 2026 21:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-54360</strong></p>
  <p>Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can craft malicious links containing JavaScript payloads that execute in victims' browsers when clicked, enabling session hijacking or credential theft.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-54360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-21627 – The vulnerability was rooted in how the Tassos Framework plugin handled specific...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21627</guid>
    <pubDate>Fri, 20 Feb 2026 15:20:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-21627</strong></p>
  <p>The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction.</p>
  <p><strong>CVSS:</strong> 9.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21625 – User provided uploads to the Easy Discuss component for Joomla aren't properly v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21625</guid>
    <pubDate>Fri, 16 Jan 2026 15:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21625</strong></p>
  <p>User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21624 – Lack of input filterung leads to a persistent XSS vulnerability in the user avat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21624</guid>
    <pubDate>Fri, 16 Jan 2026 15:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21624</strong></p>
  <p>Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21623 – Lack of input filterung leads to a persistent XSS vulnerability in the forum pos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21623</guid>
    <pubDate>Fri, 16 Jan 2026 15:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21623</strong></p>
  <p>Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-55758 – Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla wer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55758</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55758</guid>
    <pubDate>Tue, 28 Oct 2025 10:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-55758</strong></p>
  <p>Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55758">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-55757 – A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55757</guid>
    <pubDate>Sat, 25 Oct 2025 19:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-55757</strong></p>
  <p>A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-40636 – SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40636</guid>
    <pubDate>Fri, 03 Oct 2025 12:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-40636</strong></p>
  <p>SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retrieve database content via the ‘cip_vvisitcounter’ cookie at all endpoints where the plugin counts visits.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54301 – A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54301</guid>
    <pubDate>Mon, 25 Aug 2025 07:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54301</strong></p>
  <p>A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. File names are not properly escaped.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54300 – A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54300</guid>
    <pubDate>Mon, 25 Aug 2025 07:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54300</strong></p>
  <p>A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. The SVG upload feature does not sanitize uploads.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54475 – A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54475</guid>
    <pubDate>Fri, 15 Aug 2025 12:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54475</strong></p>
  <p>A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54474 – A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54474</guid>
    <pubDate>Fri, 15 Aug 2025 12:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54474</strong></p>
  <p>A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54473 – An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54473</guid>
    <pubDate>Fri, 15 Aug 2025 12:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54473</strong></p>
  <p>An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code execution via the unzip feature.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54299 – A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54299</guid>
    <pubDate>Mon, 28 Jul 2025 18:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54299</strong></p>
  <p>A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54298 – A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54298</guid>
    <pubDate>Mon, 28 Jul 2025 18:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54298</strong></p>
  <p>A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54297 – A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54297</guid>
    <pubDate>Wed, 23 Jul 2025 12:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54297</strong></p>
  <p>A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54296 – A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54296</guid>
    <pubDate>Wed, 23 Jul 2025 12:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54296</strong></p>
  <p>A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54295 – A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54295</guid>
    <pubDate>Wed, 23 Jul 2025 12:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54295</strong></p>
  <p>A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54294 – A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54294</guid>
    <pubDate>Wed, 23 Jul 2025 12:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54294</strong></p>
  <p>A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to execute arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-50127 – A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50127</guid>
    <pubDate>Wed, 23 Jul 2025 12:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-50127</strong></p>
  <p>A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-50126 – A stored XSS vulnerability in the RSBlog! component 1.11.6-1.14.5 Joomla was dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50126</guid>
    <pubDate>Fri, 18 Jul 2025 10:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-50126</strong></p>
  <p>A stored XSS vulnerability in the RSBlog! component 1.11.6-1.14.5 Joomla was discovered. The issue allows remote authenticated users to inject arbitrary web script or HTML via the jform[tags_text] parameter.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-50058 – A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50058</guid>
    <pubDate>Fri, 18 Jul 2025 10:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-50058</strong></p>
  <p>A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-50057 – A DOS vulnerability in RSFiles! component 1.16.3-1.17.7 Joomla was discovered. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50057</guid>
    <pubDate>Fri, 18 Jul 2025 10:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-50057</strong></p>
  <p>A DOS vulnerability in RSFiles! component 1.16.3-1.17.7 Joomla was discovered. The issue allows unauthenticated remote attackers to deny access to service via the search feature.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-50056 – A reflected XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 28 Joomla w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50056</guid>
    <pubDate>Fri, 18 Jul 2025 10:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-50056</strong></p>
  <p>A reflected XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 28 Joomla was discovered. The issue allows remote attackers to inject arbitrary web script or HTML via the crafted parameter.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49486 – A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49486</guid>
    <pubDate>Fri, 18 Jul 2025 10:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49486</strong></p>
  <p>A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla allows privileged users to store malicious scripts in gallery items.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49485 – A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49485</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49485</guid>
    <pubDate>Fri, 18 Jul 2025 10:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49485</strong></p>
  <p>A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49485">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49484 – A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49484</guid>
    <pubDate>Fri, 18 Jul 2025 10:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49484</strong></p>
  <p>A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid' parameter in the employee application feature.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-26855 – A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26855</guid>
    <pubDate>Fri, 18 Jul 2025 08:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-26855</strong></p>
  <p>A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-26854 – A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26854</guid>
    <pubDate>Fri, 18 Jul 2025 08:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-26854</strong></p>
  <p>A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49468 – A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49468</guid>
    <pubDate>Fri, 13 Jun 2025 10:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49468</strong></p>
  <p>A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability allows remote authenticated users to execute arbitrary SQL commands via the id_module parameter.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-49467 – A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49467</guid>
    <pubDate>Thu, 12 Jun 2025 16:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-49467</strong></p>
  <p>A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-32466 – A SQL injection vulnerability in RSMediaGallery! component 1.7.4 - 2.1.7 for Joo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32466</guid>
    <pubDate>Wed, 11 Jun 2025 20:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-32466</strong></p>
  <p>A SQL injection vulnerability in RSMediaGallery! component 1.7.4 - 2.1.7 for Joomla was discovered. The issue occurs within the dashboard  component, where user-supplied input is not properly sanitized before being stored and rendered. An attacker can inject malicious JavaScript code into text fields or other input points, which is subsequently executed in the browser of any user who clicks on th…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32465 – A stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32465</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32465</guid>
    <pubDate>Wed, 11 Jun 2025 20:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32465</strong></p>
  <p>A stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla was discovered. It allows attackers to perform cross-site scripting (XSS) attacks via sending crafted payload.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32465">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30085 – Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for J...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30085</guid>
    <pubDate>Wed, 11 Jun 2025 20:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30085</strong></p>
  <p>Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs within the submission export feature and requires administrative access to the export feature.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30084 – A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30084</guid>
    <pubDate>Thu, 05 Jun 2025 14:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30084</strong></p>
  <p>A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the dashboard  component, where user-supplied input is not properly sanitized before being stored and rendered. An attacker can inject malicious JavaScript code into text fields or other input points, which is subsequently executed in the browser of any user who clicks on the craft…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27754 – A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27754</guid>
    <pubDate>Thu, 05 Jun 2025 14:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27754</strong></p>
  <p>A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows authenticated users to inject malicious JavaScript into the plugin's resource. The injected payload is stored by the application and later executed when other users view the affected content.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27753 – A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27753</guid>
    <pubDate>Thu, 05 Jun 2025 14:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27753</strong></p>
  <p>A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. The vulnerability is due to the use of unescaped user-supplied parameters in SQL queries within the dashboard component. This allows an authenticated attacker to inject malicious SQL code through unsanitized input fields, which are used directly in SQL queries. Exploiting this flaw can lead to unauthorized d…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27445 – A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27445</guid>
    <pubDate>Thu, 05 Jun 2025 14:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27445</strong></p>
  <p>A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allows authenticated users to read arbitrary files outside the Joomla root directory. The flaw is caused by insufficient sanitization of user-supplied input in file path parameters, allowing attackers to exploit directory traversal sequences (e.g., ../) to access sensitive files</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27444 – A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27444</guid>
    <pubDate>Wed, 04 Jun 2025 08:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27444</strong></p>
  <p>A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered. The issue arises from the improper handling of the filter[dateFrom] GET parameter, which is reflected unescaped in the administrative backend interface. This allows an authenticated attacker with admin or editor privileges to inject arbitrary JavaScript code by crafting a malicious URL.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-25228 – A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25228</guid>
    <pubDate>Mon, 21 Apr 2025 08:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-25228</strong></p>
  <p>A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-25225 – A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25225</guid>
    <pubDate>Sat, 15 Mar 2025 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-25225</strong></p>
  <p>A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their privileges to Super Admin Permissions.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2127 – A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2127</guid>
    <pubDate>Sun, 09 Mar 2025 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2127</strong></p>
  <p>A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties. The manipulation of the argument Itemid/jp_yearbuilt leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2126 – A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2126</guid>
    <pubDate>Sun, 09 Mar 2025 17:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2126</strong></p>
  <p>A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties of the component GET Parameter Handler. The manipulation of the argument title leads to sql injection. The attack may be initiated remotely. The exploit has been disclose…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-22212 – A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22212</guid>
    <pubDate>Wed, 05 Mar 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-22212</strong></p>
  <p>A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the submission management area in backend.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-22211 – A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22211</guid>
    <pubDate>Tue, 25 Feb 2025 22:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-22211</strong></p>
  <p>A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the country management area in backend.</p>
  <p><strong>CVSS:</strong> 3.4 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22210 – A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22210</guid>
    <pubDate>Tue, 25 Feb 2025 06:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22210</strong></p>
  <p>A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22209 – A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22209</guid>
    <pubDate>Sat, 15 Feb 2025 09:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22209</strong></p>
  <p>A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' parameter in the Employer Payment History search feature.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22208 – A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22208</guid>
    <pubDate>Sat, 15 Feb 2025 09:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22208</strong></p>
  <p>A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' parameter in the GDPR Erase Data Request search feature.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22206 – A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22206</guid>
    <pubDate>Tue, 04 Feb 2025 15:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22206</strong></p>
  <p>A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22205 – Improper handling of input variables lead to multiple path traversal vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22205</guid>
    <pubDate>Tue, 04 Feb 2025 08:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22205</strong></p>
  <p>Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-22204 – Improper control of generation of code in the sourcerer extension for Joomla in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22204</guid>
    <pubDate>Tue, 04 Feb 2025 08:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-22204</strong></p>
  <p>Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-40745 – Reflected Cross site scripting vulnerability in Convert Forms component for Joom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40745</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40745</guid>
    <pubDate>Wed, 04 Dec 2024 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-40745</strong></p>
  <p>Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40745">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-40744 – Unrestricted file upload via security bypass in Convert Forms component for Joom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40744</guid>
    <pubDate>Wed, 04 Dec 2024 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-40744</strong></p>
  <p>Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-11145 – Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11145</guid>
    <pubDate>Tue, 26 Nov 2024 20:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-11145</strong></p>
  <p>Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! application. Fixed in versions 3.8 and 4.5.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-40746 – A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component &lt;...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40746</guid>
    <pubDate>Mon, 21 Oct 2024 17:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-40746</strong></p>
  <p>A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload in the `description` parameter of any product. The `description `parameter is not sanitised in the backend.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-27183 – XSS vulnerability in  DJ-HelpfulArticles component for Joomla.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27183</guid>
    <pubDate>Tue, 09 Jul 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-27183</strong></p>
  <p>XSS vulnerability in  DJ-HelpfulArticles component for Joomla.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5737 – Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a conte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5737</guid>
    <pubDate>Fri, 28 Jun 2024 12:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5737</strong></p>
  <p>Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data which is rendered by a webpage as HTML. This issue affects AdmirorFrames: before 5.0.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5736 – Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extens...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5736</guid>
    <pubDate>Fri, 28 Jun 2024 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5736</strong></p>
  <p>Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. This issue affects AdmirorFrames: before 5.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5735 – Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelpe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5735</guid>
    <pubDate>Fri, 28 Jun 2024 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5735</strong></p>
  <p>Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder. This issue affects AdmirorFrames: before 5.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-32788 – Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32788</guid>
    <pubDate>Wed, 24 Apr 2024 08:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-32788</strong></p>
  <p>Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Joomla to WordPress.This issue affects FG Joomla to WordPress: from n/a through 4.20.2.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-24837 – Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24837</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24837</guid>
    <pubDate>Wed, 21 Feb 2024 08:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-24837</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drupal to WordPress, Frédéric GILLES FG Joomla to WordPress.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.44.3; FG Drupal to WordPress: from n/a through 3.67.0; FG Joomla to WordPress: from n/a through 4.15.0.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24837">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21728 – An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21728</guid>
    <pubDate>Thu, 15 Feb 2024 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21728</strong></p>
  <p>An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joomla fronted integration with osTicket, a popular Support ticket system. The Open Redirect vulnerability allows attackers to control the return parameter in the URL to a base64 malicious URL.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21727 – XSS vulnerability in DP Calendar component for Joomla.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21727</guid>
    <pubDate>Thu, 15 Feb 2024 07:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21727</strong></p>
  <p>XSS vulnerability in DP Calendar component for Joomla.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-49708 – SQLi vulnerability in Starshop component for Joomla.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49708</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49708</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-49708</strong></p>
  <p>SQLi vulnerability in Starshop component for Joomla.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49708">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-49707 – SQLi vulnerability in S5 Register module for Joomla.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49707</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-49707</strong></p>
  <p>SQLi vulnerability in S5 Register module for Joomla.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40659 – A reflected XSS vulnerability was discovered in the Easy Quick Contact module fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40659</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40659</strong></p>
  <p>A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40658 – A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40658</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40658</strong></p>
  <p>A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40657 – A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40657</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40657</strong></p>
  <p>A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40656 – A reflected XSS vulnerability was discovered in the Quickform component for Joom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40656</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40656</strong></p>
  <p>A reflected XSS vulnerability was discovered in the Quickform component for Joomla.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40655 – A reflected XSS vulnerability was discovered in the Proforms Basic component for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40655</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40655</strong></p>
  <p>A reflected XSS vulnerability was discovered in the Proforms Basic component for Joomla.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-40630 – Unauthenticated LFI/SSRF in JCDashboards component for Joomla.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40630</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-40630</strong></p>
  <p>Unauthenticated LFI/SSRF in JCDashboards component for Joomla.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-40629 – SQLi vulnerability in LMS Lite component for Joomla.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40629</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-40629</strong></p>
  <p>SQLi vulnerability in LMS Lite component for Joomla.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40628 – A reflected XSS vulnerability was discovered in the Extplorer component for Joom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40628</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40628</strong></p>
  <p>A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40627 – A reflected XSS vulnerability was discovered in the LivingWord component for Joo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40627</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40627</strong></p>
  <p>A reflected XSS vulnerability was discovered in the LivingWord component for Joomla.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-39974 – Exposure of Sensitive Information vulnerability in AcyMailing Enterprise compone...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39974</guid>
    <pubDate>Thu, 17 Aug 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-39974</strong></p>
  <p>Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of subscribers in a specific list.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-39973 – Improper Access Control vulnerability in AcyMailing Enterprise component for Joo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39973</guid>
    <pubDate>Thu, 17 Aug 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-39973</strong></p>
  <p>Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-39972 – Improper Access Control vulnerability in AcyMailing Enterprise component for Joo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39972</guid>
    <pubDate>Thu, 17 Aug 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-39972</strong></p>
  <p>Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized users to create new mailing lists.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-39971 – Improper Neutralization of Input During Web Page Generation vulnerability in Acy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39971</guid>
    <pubDate>Thu, 17 Aug 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-39971</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-39970 – Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing comp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39970</guid>
    <pubDate>Thu, 17 Aug 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-39970</strong></p>
  <p>Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-38045 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38045</guid>
    <pubDate>Mon, 07 Aug 2023 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-38045</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-23756 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23756</guid>
    <pubDate>Tue, 11 Jul 2023 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-23756</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23756">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
