Joomlacalendars develops a line of calendar and event-management extensions for the Jooml platform, with its exposure centered on products such as Event Calendar, Picture Calendar, and Visual Calendar. The durable signal reflects application-layer input-handling weaknesses recurrent across these extensions, specifically SQL injection and path traversal flaws that arise in calendar data processing and file-access routines. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joomlacalendars over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6398CRITICAL SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action. | Jan 30, 2018 | 9.8 | 43 | NO | YES |
CVE-2018-6395CRITICAL SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action. | Jan 30, 2018 | 9.8 | 43 | NO | YES |
CVE-2018-6397HIGH Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter. | Jan 30, 2018 | 7.5 | 40 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joomlacalendars.
Media articles that mention a CVE ID that affects a product developed by Joomlacalendars — matched by CVE ID, not by vendor name.