ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-22212
A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute a

A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the submission management area in backend.

NVD description · AI analysis pending
2.7<1%
  • convert forms project convert forms
CVE-2024-40744
+1 in the same advisory: …40745
Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.

Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.

NVD description · AI analysis pending
9.8
group max
<1%
  • convert forms project convert forms
CVE-2018-10063
The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that is mishandled when exporting a Leads fil

The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that is mishandled when exporting a Leads file.

NVD description · AI analysis pending
7.89% PoC
  • convert forms project convert forms