2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2019-25748 — Joomla: JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25748

Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rooms parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL payloads in the rooms parameter to extract sensitive database information including version details. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20282 — Component: jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20282

Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the product_id parameter. Attackers can send GET requests to index.php with the option=com_jcart&route=product/product parameters and malicious product_id values to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20281 — Component: Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20281

Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename parameter. Attackers can send GET requests to index.php with the option=com_extrasearch parameter and malicious SQL in the establename field to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20280 — Joomla: Component Myportfolio 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20280

Joomla Component Myportfolio 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the pid parameter. Attackers can send GET requests to index.php with malicious pid values in the task=project&view=grid endpoint to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20279 — Joomla: Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20279

Joomla Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the aid parameter. Attackers can send GET requests to index.php with malicious aid values in the make_payment task to extract sensitive database information using boolean-based blind or time-based blind techniques. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20278 — Joomla: Component JoomRecipe 1.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20278

Joomla Component JoomRecipe 1.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the category parameter. Attackers can send GET requests to the all-recipes endpoint with malicious SQL payloads in the category path segment to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20277 — Joomla: JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20277

Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the search results page. Attackers can inject SQL code through POST requests to the search endpoint to extract database information using boolean-based blind SQL injection techniques. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20276 — Component: SIMGenealogy 2.1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20276

Joomla! Component SIMGenealogy 2.1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the type parameter. Attackers can send GET requests to index.php with the option=com_simgenealogy, view=latest parameters and inject malicious SQL in the type parameter to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20275 — Component: PHP-Bridge 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20275

Joomla! Component PHP-Bridge 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_phpbridge&view=phpview parameters and inject SQL code in the id parameter to extract database information including table and column names. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20274 — Joomla: LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20274

Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cp_id parameter. Attackers can send GET requests to index.php with the option=com_lmsking, view=lmsking, layout=learningpath, and task=learningPath parameters to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20273 — Joomla: Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20273

Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_registrationpro&view=category&id parameter containing SQL injection payloads to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20272 — Joomla: Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20272

Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the sf_selectuser_id parameter. Attackers can send GET requests to index.php with the option=com_upl and view=propertylisting parameters to extract sensitive database information including table names and column structures. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20271 — Joomla: StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20271

Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to index.php with the option=com_streetguess&view=maps parameters and inject SQL code in the catid parameter to extract sensitive database information including version and database names. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20270 — Component: Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20270

Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username and id parameters. Attackers can send GET requests to index.php with option=com_twitchtv and view parameters containing SQL injection payloads to extract sensitive database information including credentials and configuration data. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20269 — Component: KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20269

Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious SQL code in the kissgallery endpoint to execute arbitrary database queries and extract sensitive information. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20268 — Component: Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20268

Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter. Attackers can send GET requests to the RSVP plugin endpoint with crafted SQL payloads to extract sensitive database information including database names and table structures. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:08Z
HIGH

Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more

Metasploit Framework 6.4.137–6.4.139 adds five new exploit modules including an unauthenticated RCE chain for Paperclip AI (CVE-2026-41679), a post-exploitation NTLM relay-to-self module for Windows privilege escalation via LDAP and Shadow Credentials, VS Code extension persistence, and a Linux kernel race condition file disclosure exploit. Framework enhancements include MCP server plugin integration for AI-assisted operations within msfconsole, improved module check codes with richer detail, and search functionality refinements.

SRFApplicationSRFOsTACTA0004TACTA0001TACTA0003TACTA0008OSLinuxOSWindows
78
Edit Score
2026-06-19
2026-06-19 16:16Z
HIGH

CVE-2017-20267 — Component: Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20267

Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET requests to the events view with malicious SQL code in the category_id parameter to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 16:16Z
HIGH

CVE-2017-20266 — Joomla: SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20266

Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchword parameter to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 16:16Z
HIGH

CVE-2017-20263 — Component: FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20263

Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_focalpoint, view=location, and a crafted id parameter containing SQL commands to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 16:16Z
HIGH

CVE-2017-20262 — Component: Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20262

Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cid parameter. Attackers can send GET requests to index.php with the option=com_ajaxquiz and view=ajaxquiz parameters to extract sensitive database information including table names and column structures. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 16:16Z
HIGH

CVE-2017-20261 — Component: Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20261

Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can supply crafted SQL statements in GET requests to the brainy and alice views to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 16:16Z
HIGH

CVE-2017-20260 — Component: Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20260

Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can send requests to the subscribeajax view with crafted SQL payloads in the product_id parameter to extract sensitive database information including credentials and configuration data. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 16:16Z
HIGH

CVE-2017-20259 — Joomla: OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20259

Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_osdownloads&view=item&id=[SQL] to extract sensitive database information including credentials and configuration data. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 16:16Z
HIGH

CVE-2017-20258 — Component: RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20258

Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_pofos&view=pofo&id=[SQL] to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score