VYPR
Vendor

Rsjoomla

Products
9
CVEs
11
Across products
12
Status
Private

Products

9

Recent CVEs

11
  • CVE-2021-4226CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.01

    RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented.

  • CVE-2025-30085CriJun 11, 2025
    risk 0.60cvss epss 0.00

    Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs within the submission export feature and requires administrative access to the export feature.

  • CVE-2026-25341HigMar 25, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSJoomla! RSFirewall! rsfirewall allows Stored XSS.This issue affects RSFirewall!: from n/a through <= 1.1.45.

  • CVE-2025-27754MedJun 5, 2025
    risk 0.42cvss 6.5epss 0.00

    A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows authenticated users to inject malicious JavaScript into the plugin's resource. The injected payload is stored by the application and later executed when other…

  • CVE-2025-27753MedJun 5, 2025
    risk 0.42cvss 6.5epss 0.00

    A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. The vulnerability is due to the use of unescaped user-supplied parameters in SQL queries within the dashboard component. This allows an authenticated attacker to inject malicious SQL code…

  • CVE-2025-30084MedJun 5, 2025
    risk 0.40cvss 6.1epss 0.00

    A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properly sanitized before being stored and rendered. An attacker can inject malicious JavaScript code…

  • CVE-2025-27445MedJun 5, 2025
    risk 0.35cvss 5.4epss 0.00

    A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allows authenticated users to read arbitrary files outside the Joomla root directory. The flaw is caused by insufficient sanitization of user-supplied input in file…

  • CVE-2025-50056MedJul 18, 2025
    risk 0.33cvss epss 0.00

    A reflected XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 28 Joomla was discovered. The issue allows remote attackers to inject arbitrary web script or HTML via the crafted parameter.

  • CVE-2025-27444MedJun 4, 2025
    risk 0.31cvss 4.8epss 0.00

    A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered. The issue arises from the improper handling of the filter[dateFrom] GET parameter, which is reflected unescaped in the administrative backend interface. This allows an authenticated…

  • CVE-2010-2464Jun 25, 2010
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php.

  • CVE-2026-57827CriJul 11, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.