ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-21626
Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure

Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure

NVD description · AI analysis pending
9.2<1%
  • stackideas easydiscuss
CVE-2026-21624
+2 in the same advisory: …21623 …21625
Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.

Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.

NVD description · AI analysis pending
9.4
group max
<1%
  • stackideas easydiscuss
CVE-2023-51810
SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted reque

SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the search parameter in the Users module.

NVD description · AI analysis pending
7.51% PoC
  • stackideas easydiscuss
CVE-2018-5263
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.

The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.

NVD description · AI analysis pending
5.42% PoC
  • stackideas easydiscuss