Cwjoomla develops a focused line of Joomla extensions centered on article management and tagging functionality, with its durable vulnerability signal concentrated on SQL injection weaknesses in components such as CW Article Attachments and CW Tags. These input-handling issues reflect the complexity of safely integrating third-party modules within a shared content-management framework; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cwjoomla over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7313CRITICAL SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter. | Feb 22, 2018 | 9.8 | 50 | NO | YES |
CVE-2018-14592CRITICAL The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php. | Sep 20, 2018 | 9.8 | 43 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cwjoomla.
Media articles that mention a CVE ID that affects a product developed by Cwjoomla — matched by CVE ID, not by vendor name.