Harmistechnology maintains a focused portfolio of web-based content management and calendar components, primarily serving the Joomla ecosystem through products such as JE Messenger, JE Auto, and JE Submit. The vendor's vulnerability exposure recurs across a consistent pattern of web-application weaknesses—SQL injection, path traversal, cross-site scripting, and authorization bypass—that are typical of extension-based systems handling user input and file operations. While the disclosures span a modest product line, they frequently acquire public exploit code, reflecting the accessibility and appeal of web-facing calendar and messaging functionality to security researchers and tool developers. Defenders deploying these Joomla extensions should treat disclosed vulnerabilities as requiring prompt evaluation for active exploit availability and prioritize their environments accordingly. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Harmistechnology over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2128HIGH Directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecifi | Jun 1, 2010 | 7.5 | 47 | NO | YES |
CVE-2010-5028HIGH SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an | Nov 2, 2011 | 7.5 | 43 | NO | YES |
CVE-2018-7315CRITICAL SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter. | Feb 22, 2018 | 9.8 | 40 | NO | YES |
CVE-2018-12254HIGH router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20interest/ URI. | Jun 12, 2018 | 8.8 | 39 | NO | YES |
CVE-2010-2680MEDIUM Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla! allows remote attackers to include and execute arbitrary loc | Jul 12, 2010 | 6.8 | 39 | NO | YES |
CVE-2019-9922HIGH An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files. | Mar 29, 2019 | 7.5 | 34 | NO | YES |
CVE-2010-4862HIGH SQL injection vulnerability in the JExtensions JE Directory (com_jedirectory) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid para | Oct 5, 2011 | 7.5 | 32 | NO | YES |
CVE-2010-4365HIGH SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id par | Dec 1, 2010 | 7.5 | 32 | NO | YES |
CVE-2010-2513HIGH SQL injection vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the vi | Jun 28, 2010 | 7.5 | 32 | NO | YES |
CVE-2010-2129MEDIUM Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for Joomla! allows remote attackers to read arbitrary files via | Jun 1, 2010 | 6.8 | 32 | NO | YES |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Harmistechnology.
Media articles that mention a CVE ID that affects a product developed by Harmistechnology — matched by CVE ID, not by vendor name.