VYPR
Vendor

JNews

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2015-7341HigMar 9, 2020
    risk 0.57cvss 8.8epss 0.01

    JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.

  • CVE-2015-7342HigMar 9, 2020
    risk 0.47cvss 7.2epss 0.01

    JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field.

  • CVE-2021-24342MedJun 7, 2021
    risk 0.40cvss 6.1epss 0.02

    The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.

  • CVE-2015-7343MedMar 9, 2020
    risk 0.31cvss 4.8epss 0.01

    JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter.