Joomsky develops a focused line of Joomla-based extensions and components—including help desk, job management, ticketing, and support tools—that extend the functionality of widely deployed Joomla installations. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, reflecting the accessibility of web-application code and the attractiveness of compromised support and administrative interfaces. The exposure recurs through a durable pattern of web-application weaknesses: SQL injection, missing authorization checks, cross-site request forgery, cross-site scripting, and PHP remote file inclusion that are characteristic of server-side application logic handling user input and file operations. Defenders should treat Joomla installations running these extensions as high-value targets, prioritize patching of administrative and ticketing components, and enforce input validation and access controls at the application layer; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joomsky over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6006CRITICAL SQL Injection exists in the JS Autoz 1.0.9 component for Joomla! via the vtype, pre, or prs parameter. | Feb 17, 2018 | 9.8 | 50 | NO | YES |
CVE-2018-5994CRITICAL SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in a view_resume request. | Feb 17, 2018 | 9.8 | 43 | NO | YES |
CVE-2018-6007HIGH CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket. | Jan 29, 2018 | 8.8 | 38 | NO | YES |
CVE-2018-9183MEDIUM The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS. | Apr 2, 2018 | 5.4 | 29 | NO | YES |
CVE-2025-30878CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-support-ticket allows Path Traversal.This issue affects JS H | Apr 1, 2025 | 9.1 | 28 | NO | NO |
CVE-2019-17527CRITICAL dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Injection via the index.php?option=com_jsjobs&task=customfields. | Dec 19, 2019 | 9.8 | 28 | NO | NO |
CVE-2025-32660CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in JoomSky JS Job Manager js-jobs allows Upload a Web Shell to a Web Server.This issue affects JS Job Manager: from n/ | Apr 17, 2025 | 9.8 | 27 | NO | NO |
CVE-2022-46838CRITICAL Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issu | Dec 13, 2024 | 9.1 | 27 | NO | NO |
CVE-2026-57652MEDIUM Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions. | Jun 26, 2026 | 5.3 | 26 | NO | NO |
CVE-2025-30886CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows SQL Injection.This issue affects | Apr 1, 2025 | 10.0 | 26 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joomsky.
Media articles that mention a CVE ID that affects a product developed by Joomsky — matched by CVE ID, not by vendor name.