JextnCVEs & Vulnerabilities

8 CVEs affecting Jextn products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

classified 1com jefaqpro 1je paypervideo 1jextn faq pro 1jextn question and answer 1jextn video gallery 1membership 1reverse auction 1
CVE-2018-6579CRITICALpoc

SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.

2 Feb 2018
9.8
CVSS
CVE-2018-6578CRITICALpoc

SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.

2 Feb 2018
9.8
CVSS
CVE-2018-6577CRITICALpoc

SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.

2 Feb 2018
9.8
CVSS
CVE-2018-6575CRITICALpoc

SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request.

2 Feb 2018
9.8
CVSS
CVE-2017-17875CRITICALpoc

The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.

27 Dec 2017
9.8
CVSS
CVE-2017-17872CRITICALpoc

The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.

27 Dec 2017
9.8
CVSS
CVE-2017-17871CRITICALpoc

The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.

27 Dec 2017
9.8
CVSS
CVE-2010-3211HIGHpoc

Multiple SQL injection vulnerabilities in the JE FAQ Pro (com_jefaqpro) component 1.5.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via category categorylist operations with (1) the catid parameter or (2) the catid parameter in a lists action.

3 Sep 2010
7.5
CVSS
← PrevPage 1 / 1Next →