Stackideas develops a focused portfolio of community and discussion-forum extensions for Joomla, with its primary products EasyDiscuss and Komento serving as customization layers for user-generated content workflows. The vendor's vulnerability profile centers on web-application input-handling and file-upload weaknesses, including cross-site scripting, SQL injection, and unrestricted file uploads, alongside exposure of sensitive information—a pattern consistent with the attack surface inherent to forum software that processes and stores user submissions. The disclosures attract public exploit tooling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stackideas over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5263MEDIUM The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS. | Jan 8, 2018 | 5.4 | 30 | NO | YES |
CVE-2026-21625HIGH User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening. | Jan 16, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-21626HIGH Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure | Feb 6, 2026 | 7.5 | 25 | NO | NO |
CVE-2023-51810HIGH SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the search par | Jan 16, 2024 | 7.5 | 24 | NO | NO |
CVE-2026-21624MEDIUM Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla. | Jan 16, 2026 | 5.4 | 23 | NO | NO |
CVE-2026-21623MEDIUM Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla. | Jan 16, 2026 | 5.4 | 23 | NO | NO |
CVE-2015-7324MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla! allow remote attackers to inje | Dec 27, 2017 | 6.1 | 22 | NO | NO |
CVE-2014-0793MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for Joomla! allow remote attackers to inject arbitrary web script | Jan 30, 2014 | 4.3 | 21 | NO | YES |
CVE-2014-1837MEDIUM Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML v | Jan 30, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stackideas.
Media articles that mention a CVE ID that affects a product developed by Stackideas — matched by CVE ID, not by vendor name.