Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-22212 | A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute a A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the submission management area in backend. NVD description · AI analysis pending | 2.7 | <1% |
| — | ||
| CVE-2024-40744 +1 in the same advisory: …40745 | Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8. Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2018-10063 | The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that is mishandled when exporting a Leads fil The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that is mishandled when exporting a Leads file. NVD description · AI analysis pending | 7.8 | 9% | PoC |
| — |