VYPR
Vendor

Stackideas

Products
2
CVEs
9
Across products
9
Status
Private

Products

2

Recent CVEs

9
  • CVE-2026-21625HigJan 16, 2026
    risk 0.57cvss 8.8epss 0.00

    User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.

  • CVE-2026-21626HigFeb 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure

  • CVE-2023-51810HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the search parameter in the Users module.

  • CVE-2015-7324MedDec 27, 2017
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) img or (2) url tag of a new comment.

  • CVE-2018-5263MedJan 8, 2018
    risk 0.38cvss 5.4epss 0.02

    The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.

  • CVE-2026-21624MedJan 16, 2026
    risk 0.35cvss 5.4epss 0.00

    Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.

  • CVE-2026-21623MedJan 16, 2026
    risk 0.35cvss 5.4epss 0.00

    Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.

  • CVE-2014-0793Jan 30, 2014
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website or (2) latitude parameter in a comment to the default URI.

  • CVE-2014-1837Jan 30, 2014
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors related to "checking new comments."