Joommasters develops a portfolio of Joomla extensions and plugins spanning blogging, navigation, media, and page-building functionality, a modestly represented but notably prominent niche within the CMS ecosystem. Its vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrating in recurring weakness classes of SQL injection and unrestricted file upload that are characteristic of web-application plugins with insufficient input validation and access controls. Defenders should treat this vendor's advisories with high priority given the severity tendency; live exploitation activity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joommasters over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27034CRITICAL PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability. | Mar 23, 2023 | 9.8 | 73 | NO | YES |
CVE-2018-6581CRITICAL SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter. | Feb 2, 2018 | 9.8 | 42 | NO | YES |
CVE-2023-29632CRITICAL PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php. | Jun 6, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-29631CRITICAL PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php. | Jun 5, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-29630CRITICAL PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php. | Jun 5, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-50030CRITICAL In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0. The method `JmsSetting::getSecondImgs()` has a sen | Jan 19, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joommasters.
Media articles that mention a CVE ID that affects a product developed by Joommasters — matched by CVE ID, not by vendor name.