Fabrik
by Fabrikar
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-76605 | Cri | 0.65 | — | 0.01 | Aug 22, 2026 | Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2. | ||
| CVE-2026-76604 | Cri | 0.65 | — | 0.01 | Aug 22, 2026 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes. | ||
| CVE-2026-66915 | Cri | 0.65 | — | 0.01 | Aug 10, 2026 | Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin. | ||
| CVE-2026-76602 | Cri | 0.60 | — | 0.00 | Aug 22, 2026 | Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors. | ||
| CVE-2018-10727 | Med | 0.40 | 6.1 | 0.01 | Oct 29, 2019 | Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component through v3.8.1 for Joomla! allows remote attackers to inject arbitrary web script via the HTTP Referer header. | ||
| CVE-2010-1981 | 0.04 | — | 0.12 | May 19, 2010 | Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |||
| CVE-2011-5004 | 0.00 | — | 0.02 | Dec 25, 2011 | Unrestricted file upload vulnerability in models/importcsv.php in the Fabrik (com_fabrik) component before 2.1.1 for Joomla! allows remote authenticated users with Manager privileges to execute arbitrary code by uploading a file with an executable extension, then accessing it… |
- risk 0.65cvss —epss 0.01
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.
- risk 0.65cvss —epss 0.01
Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes.
- risk 0.65cvss —epss 0.01
Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.
- risk 0.60cvss —epss 0.00
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.
- risk 0.40cvss 6.1epss 0.01
Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component through v3.8.1 for Joomla! allows remote attackers to inject arbitrary web script via the HTTP Referer header.
- CVE-2010-1981May 19, 2010risk 0.04cvss —epss 0.12
Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
- CVE-2011-5004Dec 25, 2011risk 0.00cvss —epss 0.02
Unrestricted file upload vulnerability in models/importcsv.php in the Fabrik (com_fabrik) component before 2.1.1 for Joomla! allows remote authenticated users with Manager privileges to execute arbitrary code by uploading a file with an executable extension, then accessing it…