ThephpfactoryCVEs & Vulnerabilities

11 CVEs affecting Thephpfactory products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

penny auction factory 1jobs factory 1article factory manager 1social factory 1raffle factory 1dutch auction factory 1auction factory 1micro deal factory 1
CVE-2018-17386CRITICAL

SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.

19 Jun 2019
9.8
CVSS
CVE-2018-17381CRITICAL

SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.

19 Jun 2019
9.8
CVSS
CVE-2018-17374CRITICAL

SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.

19 Jun 2019
9.8
CVSS
CVE-2018-17385CRITICALpoc

SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.

28 Sep 2018
9.8
CVSS
CVE-2018-17384CRITICALpoc

SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.

28 Sep 2018
9.8
CVSS
CVE-2018-17383CRITICALpoc

SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.

28 Sep 2018
9.8
CVSS
CVE-2018-17382CRITICALpoc

SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.

28 Sep 2018
9.8
CVSS
CVE-2018-17380CRITICALpoc

SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.

28 Sep 2018
9.8
CVSS
CVE-2018-17379CRITICALpoc

SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.

28 Sep 2018
9.8
CVSS
CVE-2018-17378CRITICALpoc

SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.

28 Sep 2018
9.8
CVSS
CVE-2018-17376CRITICALpoc

SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.

28 Sep 2018
9.8
CVSS
← PrevPage 1 / 1Next →
Thephpfactory CVEs & Vulnerabilities — 11 Tracked