VYPR
Vendor

JDownloads

Products
2
CVEs
7
Across products
7
Status
Private

Products

2

Recent CVEs

7
  • CVE-2020-19455HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    SQL injection exists in the jdownloads 3.2.63 component for Joomla! via components/com_jdownloads/helpers/categories.php, order function via the filter_order parameter.

  • CVE-2020-19451HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, updateLog function via the X-forwarded-for Header parameter.

  • CVE-2020-19450HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, getUserLimits function in the list parameter.

  • CVE-2020-19447HigSep 24, 2020
    risk 0.49cvss 7.5epss 0.01

    SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_files_id parameter.

  • CVE-2018-10068MedApr 12, 2018
    risk 0.43cvss 6.1epss 0.04

    The jDownloads extension before 3.2.59 for Joomla! has XSS.

  • CVE-2025-55758MedOct 28, 2025
    risk 0.35cvss 5.4epss 0.00

    Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered.

  • CVE-2022-27909MedMay 6, 2022
    risk 0.28cvss 4.3epss 0.01

    In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files