CVE-2025-49467
critical · 9.3A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.
9.3
CVSS
0.3%
EPSS (exploit prob.)
25th
EPSS percentile
2025-06-12
Published
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Amber
Weaknesses
CWE-89
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-49467