joommasters records
6 published records for vendor joommasters.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2023-27034Proof of concept | PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.joommasters · jms blog · CWE-89 | Critical9.8 | — | 58.7% | Mar 23, 2023 |
40Plan | CVE-2018-6581Proof of concept | SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter.joommasters · jms music · CWE-89 | Critical9.8 | — | 2.7% | Feb 2, 2018 |
39Monitor | CVE-2023-29630No exploit | PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php.joommasters · jms drop mega menu · CWE-89 | Critical9.8 | — | 1.0% | Jun 5, 2023 |
39Monitor | CVE-2023-29632No exploit | PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php.joommasters · jmspagebuilder · CWE-89 | Critical9.8 | — | 1.0% | Jun 6, 2023 |
39Monitor | CVE-2023-29631No exploit | PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php.joommasters · jms slider · CWE-434 | Critical9.8 | — | 0.7% | Jun 5, 2023 |
39Monitor | CVE-2023-50030No exploit | In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0.joommasters · jmssetting · CWE-89 | Critical9.8 | — | 0.7% | Jan 19, 2024 |
- CVE-2023-2703457Plan
PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.
CriticalCVSS 9.8Proof of conceptEPSS 59%joommasters · jms blogMar 23, 2023
- CVE-2018-658140Plan
SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter.
CriticalCVSS 9.8Proof of conceptEPSS 3%joommasters · jms musicFeb 2, 2018
- CVE-2023-2963039Monitor
PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php.
CriticalCVSS 9.8No exploitEPSS 1%joommasters · jms drop mega menuJun 5, 2023
- CVE-2023-2963239Monitor
PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php.
CriticalCVSS 9.8No exploitEPSS 1%joommasters · jmspagebuilderJun 6, 2023
- CVE-2023-2963139Monitor
PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php.
CriticalCVSS 9.8No exploitEPSS 1%joommasters · jms sliderJun 5, 2023
- CVE-2023-5003039Monitor
In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0.
CriticalCVSS 9.8No exploitEPSS 1%joommasters · jmssettingJan 19, 2024