Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-7228

67
FAUCET Score

CVE-2014-7228 describes a critical vulnerability in Akeeba Restore and related Akeeba products for Joomla and WordPress, affecting versions across multiple product lines. The flaw allows remote attackers to bypass encryption and execute arbitrary code by manipulating GET and POST parameters during backup or update operations, leading to the extraction of crafted archives. With a CVSS score of 7.5 and a FAUCET Risk Score of 96/100, this vulnerability is considered highly severe due to its network-based attack vector, low access complexity, and potential for complete compromise (confidentiality, integrity, and availability). Exploit intelligence indicates the existence of a Metasploit module (EDB-35033) for remote code execution, confirming readily available exploit code, though there is no evidence of active exploitation in the wild or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
2.5.4CPE matchmatch criteria
cpe:2.3:a:joomla:joomla\!:2.5.4:*:*:*:*:*:*:*
2.5.5CPE matchmatch criteria
cpe:2.3:a:joomla:joomla\!:2.5.5:*:*:*:*:*:*:*
2.5.6CPE matchmatch criteria
cpe:2.3:a:joomla:joomla\!:2.5.6:*:*:*:*:*:*:*
2.5.7CPE matchmatch criteria
cpe:2.3:a:joomla:joomla\!:2.5.7:*:*:*:*:*:*:*
2.5.8CPE matchmatch criteria
cpe:2.3:a:joomla:joomla\!:2.5.8:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
55.13%
Probability of exploitation in next 30 days
EPSS Percentile
98.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
Metasploit: Joomla Akeeba Kickstart Unserialize Remote Code Execution · Sep 29, 2014
ExploitDB: EDB-35033 · Oct 21, 2014
This CVE's current EPSS score of 0.5513 is in the 98th percentile among its peer group of 51,553 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

developer.joomla.org / security/595-20140903-core-remote-file-inclusion.html
Vendor Advisory
akeebabackup.com / home/news/1605-security-update-sep-2014.html
Vendor Advisory
websec.wordpress.com / 2014/10/05/joomla-3-3-4-akeeba-kickstart-remote-code-execution-cve-2014-7228
Exploit