VYPR

Fabrik

by Fabrikar

CVEs (7)

  • CVE-2026-76605CriAug 22, 2026
    risk 0.65cvss —epss 0.01

    Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.

  • CVE-2026-76604CriAug 22, 2026
    risk 0.65cvss —epss 0.01

    Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes.

  • CVE-2026-66915CriAug 10, 2026
    risk 0.65cvss —epss 0.01

    Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

  • CVE-2026-76602CriAug 22, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.

  • CVE-2018-10727MedOct 29, 2019
    risk 0.40cvss 6.1epss 0.01

    Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component through v3.8.1 for Joomla! allows remote attackers to inject arbitrary web script via the HTTP Referer header.

  • CVE-2010-1981May 19, 2010
    risk 0.04cvss —epss 0.12

    Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

  • CVE-2011-5004Dec 25, 2011
    risk 0.00cvss —epss 0.02

    Unrestricted file upload vulnerability in models/importcsv.php in the Fabrik (com_fabrik) component before 2.1.1 for Joomla! allows remote authenticated users with Manager privileges to execute arbitrary code by uploading a file with an executable extension, then accessing it…