Joobi's vulnerability footprint centers on a narrow line of content-management and e-commerce components for the Joomla platform, including JNews, Acajoom, and JStore, which serve as widely adopted extensions across Joomla-based websites. The recurring exposure spans web-tier input-handling weaknesses—cross-site scripting, SQL injection, path traversal, and unrestricted file upload—alongside information-disclosure flaws that are characteristic of application-layer plugins with insufficient input sanitization and access controls. Public exploit code frequently becomes available for this vendor's disclosures, reflecting the appeal of plugin vulnerabilities to web-focused attackers and the accessibility of Joomla installations to security researchers. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joobi over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-5286HIGH Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. ( | Nov 26, 2012 | 10.0 | 54 | NO | YES |
CVE-2008-1427HIGH SQL injection vulnerability in the Joobi Acajoom (com_acajoom) 1.1.5 and 1.2.5 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mailingid par | Mar 20, 2008 | 7.5 | 31 | NO | YES |
CVE-2015-7341HIGH JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension. | Mar 9, 2020 | 8.8 | 23 | NO | NO |
CVE-2013-1636MEDIUM Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNew | Mar 12, 2014 | 4.3 | 23 | NO | YES |
CVE-2015-7342HIGH JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field. | Mar 9, 2020 | 7.2 | 19 | NO | NO |
CVE-2012-4256MEDIUM The jNews (com_jnews) component 7.5.1 for Joomla! allows remote attackers to obtain sensitive information via the emailsearch parameter, which reveals the installation path in an e | Aug 13, 2012 | 5.0 | 18 | NO | NO |
CVE-2015-7343MEDIUM JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter. | Mar 9, 2020 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joobi.
Media articles that mention a CVE ID that affects a product developed by Joobi — matched by CVE ID, not by vendor name.