VYPR

Joomdle

by Joomla

CVEs (3)

  • CVE-2010-2908Jul 28, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the Joomdle (com_joomdle) component 0.24 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the course_id parameter in a detail action to index.php.

  • CVE-2026-65882MedJul 28, 2026
    risk 0.00cvss 6.1epss 0.00

    Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle wrapper endpoint allowed a reflected XSS vector.

  • CVE-2026-65881HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read access and password reset of CMS accounts.