VYPR
Vendor

Jevents

Products
2
CVEs
3
Across products
3
Status
Private

Products

2

Recent CVEs

3
  • CVE-2025-49467CriJun 12, 2025
    risk 0.60cvss epss 0.00

    A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.

  • CVE-2015-7340HigMar 9, 2020
    risk 0.47cvss 7.2epss 0.01

    JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action.

  • CVE-2010-0635Feb 12, 2010
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in the plgSearchEventsearch::onSearch method in eventsearch.php in the JEvents Search plugin 1.5 through 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some of these details are obtained…