Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Easydiscuss HIGH 7.5
CVE-2026-21626

Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information discl…

Fix: after 5.0.15
Fix from $1,950 2026-02-06
Easydiscuss HIGH 8.8
CVE-2026-21625

User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type…

Fix: after 5.0.15
Fix from $1,950 2026-01-16
Easydiscuss MEDIUM 5.4
CVE-2026-21623

Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.

Fix: after 5.0.15
Fix from $1,600 2026-01-16
Easydiscuss MEDIUM 5.4
CVE-2026-21624

Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.

Fix: after 5.0.15
Fix from $1,600 2026-01-16
Easydiscuss HIGH 7.5
CVE-2023-51810

SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a cr…

Fix: 5.0.10+
Fix from $1,950 2024-01-16
Easydiscuss MEDIUM 5.4
CVE-2018-5263

The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.

Fix: 4.0.21+
Fix from $1,600 2018-01-08
Komento MEDIUM 6.1
CVE-2015-7324

Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla!…

Fix: 2.0.5+
Fix from $1,600 2017-12-27