VYPR

sourcerer

by Joomla

CVEs (2)

  • CVE-2025-22204CriFeb 4, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.

  • CVE-2026-64796CriJul 22, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP…