Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Stackideas

First CVE: Jan 30, 2014Active for: 12 yearsTotal CVEs: 9

Stackideas develops a focused portfolio of community and discussion-forum extensions for Joomla, with its primary products EasyDiscuss and Komento serving as customization layers for user-generated content workflows. The vendor's vulnerability profile centers on web-application input-handling and file-upload weaknesses, including cross-site scripting, SQL injection, and unrestricted file uploads, alongside exposure of sensitive information—a pattern consistent with the attack surface inherent to forum software that processes and stores user submissions. The disclosures attract public exploit tooling. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Stackideas over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2014
12 years ago
Most Recent CVE
Feb 6, 2026
168 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-5263MEDIUM
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
Jan 8, 20185.430NOYES
CVE-2026-21625HIGH
User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.
Jan 16, 20268.827NONO
CVE-2026-21626HIGH
Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure
Feb 6, 20267.525NONO
CVE-2023-51810HIGH
SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the search par
Jan 16, 20247.524NONO
CVE-2026-21624MEDIUM
Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.
Jan 16, 20265.423NONO
CVE-2026-21623MEDIUM
Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.
Jan 16, 20265.423NONO
CVE-2015-7324MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla! allow remote attackers to inje
Dec 27, 20176.122NONO
CVE-2014-0793MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for Joomla! allow remote attackers to inject arbitrary web script
Jan 30, 20144.321NOYES
CVE-2014-1837MEDIUM
Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML v
Jan 30, 20144.314NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
67%
33%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network7 (77.8%)
Unknown2 (22.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (77.8%)
High0 (0.0%)
Unknown2 (22.2%)
User Interaction
None3 (33.3%)
Unknown2 (22.2%)
Required4 (44.4%)
Privileges Required
Low4 (44.4%)
High0 (0.0%)
None3 (33.3%)
Unknown2 (22.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
22.2% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Stackideas.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Stackideas — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Stackideas's Products

View all 2 CNAs →

Top CWEs