Kubik Rubik's vulnerability footprint is narrowly scoped to a pair of Joomla extension products—Simple Image Gallery Extended and Easy Joomla Backup—that serve web content management and backup functions. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kubik Rubik over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16356MEDIUM Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/conte | Feb 20, 2018 | 6.1 | 31 | NO | YES |
CVE-2018-7717MEDIUM The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demon | Mar 5, 2018 | 6.1 | 21 | NO | NO |
CVE-2017-2550HIGH Vulnerability in Easy Joomla Backup v3.2.4. The software creates a copy of the backup in the web root with an easily guessable filename. | Sep 8, 2017 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kubik Rubik.
Media articles that mention a CVE ID that affects a product developed by Kubik Rubik — matched by CVE ID, not by vendor name.