Percha's vulnerability footprint centers on a narrow suite of web-application and content-management extensions, predominantly its gallery, category tree, downloads, fields, and image-attachment modules. The recurring exposure reflects classic web-application input-handling weaknesses—path traversal and SQL injection—that arise in user-facing file and data processing, and these vulnerabilities frequently acquire public exploit tooling. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Percha over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2033HIGH Directory traversal vulnerability in the Percha Multicategory Article (com_perchacategoriestree) component 0.6 for Joomla! allows remote attackers to read arbitrary files and possi | May 25, 2010 | 7.5 | 47 | NO | YES |
CVE-2010-2035HIGH Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary files and possibly have unspeci | May 25, 2010 | 7.5 | 46 | NO | YES |
CVE-2010-2036HIGH Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have u | May 25, 2010 | 7.5 | 44 | NO | YES |
CVE-2010-2034HIGH Directory traversal vulnerability in the Percha Image Attach (com_perchaimageattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have uns | May 25, 2010 | 7.5 | 44 | NO | YES |
CVE-2010-2037HIGH Directory traversal vulnerability in the Percha Downloads Attach (com_perchadownloadsattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly | May 25, 2010 | 7.5 | 43 | NO | YES |
CVE-2010-0694HIGH SQL injection vulnerability in the PerchaGallery (com_perchagallery) component before 1.5b for Joomla! allows remote attackers to execute arbitrary SQL commands via the id paramete | Feb 23, 2010 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Percha.
Media articles that mention a CVE ID that affects a product developed by Percha — matched by CVE ID, not by vendor name.