Joomlaextensions develops a narrow set of components and extensions for the Joomla content management system, with observed vulnerabilities clustering around application-layer input-handling flaws such as SQL injection and cross-site scripting. The recurring issues in products like HMCommunity and Component Appointment reflect the web-application context and the parsing demands inherent to user-facing CMS plugins; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joomlaextensions over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12758CRITICAL https://www.joomlaextensions.co.in/ Joomla! Component Appointment 1.1 is affected by: SQL Injection. The impact is: Code execution (remote). The component is: com_appointment compo | May 9, 2019 | 9.8 | 32 | NO | NO |
CVE-2011-4808HIGH SQL injection vulnerability in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter i | Dec 14, 2011 | 7.5 | 31 | NO | YES |
CVE-2011-4809MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allow remote attackers to inject arbitrary web script or | Dec 14, 2011 | 4.3 | 23 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joomlaextensions.
Media articles that mention a CVE ID that affects a product developed by Joomlaextensions — matched by CVE ID, not by vendor name.