VYPR

GeoIP extension

by Regularlabs.com

CVEs (4)

  • CVE-2026-64875Jul 23, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.

  • CVE-2026-64876Jul 23, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.

  • CVE-2026-65430Jul 23, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.

  • CVE-2026-65431Jul 23, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.