Jdownloads is a file-management component for Joomla that maintains a narrowly scoped but notable presence in web-application deployments. Its vulnerability footprint concentrates on web-layer input handling, with recurring issues centered on SQL injection and cross-site scripting that reflect the application's need to sanitize user-supplied parameters and dynamically generated content. Public exploit code has been developed for vulnerabilities affecting this component; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jdownloads over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10068MEDIUM The jDownloads extension before 3.2.59 for Joomla! has XSS. | Apr 12, 2018 | 6.1 | 28 | NO | YES |
CVE-2020-19455HIGH SQL injection exists in the jdownloads 3.2.63 component for Joomla! via components/com_jdownloads/helpers/categories.php, order function via the filter_order parameter. | Sep 25, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-19451HIGH SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, updateLog function via the X-forwarded-for Header parameter. | Sep 25, 2020 | 7.5 | 23 | NO | NO |
CVE-2020-19450HIGH SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, getUserLimits function in the list parameter. | Sep 25, 2020 | 7.5 | 23 | NO | NO |
CVE-2020-19447HIGH SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_files_id parameter. | Sep 24, 2020 | 7.5 | 19 | NO | NO |
CVE-2022-27909MEDIUM In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files | May 6, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jdownloads.
Media articles that mention a CVE ID that affects a product developed by Jdownloads — matched by CVE ID, not by vendor name.