Ijoomla develops a modestly represented suite of Joomla extensions and components including advertising, content management, news portal, RSS feed, and knowledge-base products that extend the Joomla CMS platform. The observed vulnerability profile centers on application-layer input-handling and access-control weaknesses: SQL injection, code injection, path traversal, and improper default permissions that are characteristic of server-side template and plugin architectures. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ijoomla over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1312MEDIUM Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the | Apr 8, 2010 | 5.0 | 39 | NO | YES |
CVE-2010-4918HIGH PHP remote file inclusion vulnerability in iJoomla Magazine (com_magazine) component 3.0.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the config | Oct 8, 2011 | 7.5 | 32 | NO | YES |
CVE-2018-5696CRITICAL The iJoomla com_adagency plugin 6.0.9 for Joomla! allows SQL injection via the `advertiser_status` and `status_select` parameters to index.php. | Jan 14, 2018 | 9.8 | 29 | NO | NO |
CVE-2009-2099HIGH SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in an | Jun 17, 2009 | 7.5 | 28 | NO | YES |
CVE-2022-23802HIGH Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to private information and componen | May 6, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ijoomla.
Media articles that mention a CVE ID that affects a product developed by Ijoomla — matched by CVE ID, not by vendor name.