Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2019-25758 — Joomla! Component vBizz 1.0.7 Remote Code Execution

Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submitting malicious files through the profile_pi…

Remote | Authentication
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
7.1 HIGH
CVE-2019-25757 — Joomla vWishlist 1.0.1 SQL Injection via vproductid Parameter

Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vproductid and userid param…

Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
0.0 NA
CVE-2026-49290 — Slopsmith has path traversal in archive extractors that allows arbitrary file write → pot…

Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Prior to 0.2.9-alpha.5, a path-traversal vulnerability in Slopsmith's archive ext…

| Path Traversal
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.2 HIGH
CVE-2019-25756 — Joomla! Component vAccount 2.0.2 SQL Injection via vaccount-dashboard

Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vid parameter. …

Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.2 HIGH
CVE-2019-25755 — Joomla vReview 1.9.11 SQL Injection via editReview

Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cmId parameter. …

Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.2 HIGH
CVE-2019-25754 — Joomla vRestaurant 1.9.4 SQL Injection via menu-listing-layout

Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keysearch par…

Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.2 HIGH
CVE-2019-25753 — Joomla! Component VMap 1.9.6 SQL Injection via loadmarker

Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the latlngbound parameter.…

Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
6.5 MEDIUM
CVE-2026-49271 — libheif: Wrapped icef compressed-unit range check causes out-of-bounds read in uncompress…

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Becau…

Remote | Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.2 HIGH
CVE-2019-25752 — Joomla! Component J-BusinessDirectory 4.9.7 SQL Injection

Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type…

Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.2 HIGH
CVE-2019-25751 — Joomla J-ClassifiedsManager 3.0.5 SQL Injection

Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST par…

Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.2 HIGH
CVE-2019-25750 — Joomla J-MultipleHotelReservation 6.0.7 SQL Injection

Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through th…

Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
6.5 MEDIUM
CVE-2026-49359 — PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` fetches the content of option values server-side via `file_get_…

Remote | Server-Side Request Forgery
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
7.1 HIGH
CVE-2019-25749 — Joomla J-CruisePortal 6.0.4 SQL Injection via cruises

Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the guest_adult parameter.…

Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.1 HIGH
CVE-2026-49286 — PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case…

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` guarded the output filename against the `phar://` stream wrappe…

Remote | Misconfiguration
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.8 HIGH
CVE-2019-25748 — Joomla JHotelReservation 6.0.7 SQL Injection via search-hotels

Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rooms parameter. …

Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.2 HIGH
CVE-2026-49260 — PhpWeasyPrint: shell command injection via configurable WeasyPrint binary path due to inv…

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the shell command for WeasyPrint by passing the binary p…

| Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.8 HIGH
CVE-2017-20282 — Joomla! Component jCart for OpenCart 2.0 SQL Injection

Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the product_id para…

Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.8 HIGH
CVE-2017-20281 — Joomla! Component Extra Search 2.2.8 SQL Injection

Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename paramet…

Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.8 HIGH
CVE-2017-20280 — Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter

Joomla Component Myportfolio 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the pid parameter. Attack…

Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.8 HIGH
CVE-2017-20279 — Joomla Payage 2.05 SQL Injection via aid Parameter

Joomla Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the aid parameter. Attackers can send GET…

Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
Showing 20 of 7584 Results