Jextn develops a narrow portfolio of web-based question-and-answer and FAQ management products, with a durable vulnerability pattern centered on SQL injection flaws in their input-handling layers. The vendor's disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the exposure of database-backed web applications to direct query manipulation. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jextn over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6578CRITICAL SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request. | Feb 2, 2018 | 9.8 | 44 | NO | YES |
CVE-2018-6577CRITICAL SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request. | Feb 2, 2018 | 9.8 | 43 | NO | YES |
CVE-2018-6579CRITICAL SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request. | Feb 2, 2018 | 9.8 | 42 | NO | YES |
CVE-2017-17871CRITICAL The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter. | Dec 27, 2017 | 9.8 | 42 | NO | YES |
CVE-2018-6575CRITICAL SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request. | Feb 2, 2018 | 9.8 | 40 | NO | YES |
CVE-2017-17875CRITICAL The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action. | Dec 27, 2017 | 9.8 | 38 | NO | YES |
CVE-2017-17872CRITICAL The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action. | Dec 27, 2017 | 9.8 | 38 | NO | YES |
CVE-2010-3211HIGH Multiple SQL injection vulnerabilities in the JE FAQ Pro (com_jefaqpro) component 1.5.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via category categoryli | Sep 3, 2010 | 7.5 | 31 | NO | YES |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jextn.
Media articles that mention a CVE ID that affects a product developed by Jextn — matched by CVE ID, not by vendor name.