← All CVEs

CVE-2025-49467

critical · 9.3

A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.

9.3
CVSS
0.3%
EPSS (exploit prob.)
25th
EPSS percentile
2025-06-12
Published

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Amber

Weaknesses

CWE-89

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-49467