VYPR

Jdownloads

by JDownloads

CVEs (6)

  • CVE-2020-19455HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    SQL injection exists in the jdownloads 3.2.63 component for Joomla! via components/com_jdownloads/helpers/categories.php, order function via the filter_order parameter.

  • CVE-2020-19451HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, updateLog function via the X-forwarded-for Header parameter.

  • CVE-2020-19450HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, getUserLimits function in the list parameter.

  • CVE-2020-19447HigSep 24, 2020
    risk 0.49cvss 7.5epss 0.01

    SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_files_id parameter.

  • CVE-2018-10068MedApr 12, 2018
    risk 0.43cvss 6.1epss 0.05

    The jDownloads extension before 3.2.59 for Joomla! has XSS.

  • CVE-2022-27909MedMay 6, 2022
    risk 0.28cvss 4.3epss 0.01

    In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files