Joovili maintains a narrowly scoped product line centered on its core platform, which despite modest disclosure volume occupies a more prominent position in the vulnerability landscape than typical for its size. The vendor's disclosed vulnerabilities recur through application-layer weakness classes including path traversal, SQL injection, improper authentication, and code injection, pointing to input-validation and access-control challenges common to web-facing platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joovili over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0743HIGH PHP remote file inclusion vulnerability in members_help.php in Joovili 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the hlp parameter. | Feb 13, 2008 | 10.0 | 35 | NO | YES |
CVE-2008-6269HIGH Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, an | Feb 25, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-2063HIGH SQL injection vulnerability in browse.videos.php in Joovili 3.1 allows remote attackers to execute arbitrary SQL commands via the category parameter. | May 2, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-6620MEDIUM Directory traversal vulnerability in include/images.inc.php in Joovili 2.x allows remote attackers to read arbitrary files via a .. (dot dot) in the picture parameter. | Jan 4, 2008 | 6.4 | 28 | NO | YES |
CVE-2008-4711MEDIUM SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) vie | Oct 23, 2008 | 6.8 | 26 | NO | YES |
CVE-2007-6621MEDIUM Directory traversal vulnerability in joovili.images.php in Joovili 3.0.0 through 3.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the picture parameter. | Jan 4, 2008 | 6.4 | 26 | NO | YES |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joovili.
Media articles that mention a CVE ID that affects a product developed by Joovili — matched by CVE ID, not by vendor name.