Foobla's vulnerability profile centers on a compact set of suggestion and recommendation products, with the durable signal reflecting application-layer input-handling weaknesses including path traversal and SQL injection. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Foobla over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4804MEDIUM Directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the contro | Dec 14, 2011 | 5.0 | 45 | NO | YES |
CVE-2010-2920MEDIUM Directory traversal vulnerability in the Foobla Suggestions (com_foobla_suggestions) component 1.5.1.2 for Joomla! allows remote attackers to read arbitrary files via directory tra | Jul 30, 2010 | 6.8 | 38 | NO | YES |
CVE-2009-3669HIGH SQL injection vulnerability in the foobla Suggestions (com_foobla_suggestions) component 1.5.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the idea_i | Oct 11, 2009 | 7.5 | 29 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Foobla.
Media articles that mention a CVE ID that affects a product developed by Foobla — matched by CVE ID, not by vendor name.