VYPR

Fabrik

by Fabrikar

CVEs (20)

  • CVE-2026-66915CriAug 10, 2026
    risk 0.65cvss epss 0.01

    Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

  • CVE-2018-10727MedOct 29, 2019
    risk 0.40cvss 6.1epss 0.01

    Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component through v3.8.1 for Joomla! allows remote attackers to inject arbitrary web script via the HTTP Referer header.

  • CVE-2010-1981May 19, 2010
    risk 0.04cvss epss 0.12

    Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

  • CVE-2026-76606Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.

  • CVE-2026-77027Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector.

  • CVE-2026-76602Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.3 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.

  • CVE-2026-76603Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.3 - The inineedit form controller does not perform any access checks, disclosing items to unauthorized users.

  • CVE-2026-76571Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.3 - The condition parameter passed to a list filter is concatenated verbatim into the WHERE clause built by getFilterQuery(). An unauthenticated attacker can supply…

  • CVE-2026-76597Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot.

  • CVE-2026-76598Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary directory listings.

  • CVE-2026-76596Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table

  • CVE-2026-77992Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.

  • CVE-2026-76600Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access checks.

  • CVE-2026-76604Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The PHP form element is vulnerable to the execution of user provided codes.

  • CVE-2026-76607Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.3 - ???.

  • CVE-2026-76609Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.

  • CVE-2026-76608Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.

  • CVE-2026-76599Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows listings of arbitrary database tables including columns.

  • CVE-2026-76601Aug 22, 2026
    risk 0.00cvss epss

    Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks.

  • CVE-2011-5004Dec 25, 2011
    risk 0.00cvss epss 0.02

    Unrestricted file upload vulnerability in models/importcsv.php in the Fabrik (com_fabrik) component before 2.1.1 for Joomla! allows remote authenticated users with Manager privileges to execute arbitrary code by uploading a file with an executable extension, then accessing it…