Joomlashack records
2 published records for vendor joomlashack.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-17399No exploit | The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment.joomlashack · shack forms pro · CWE-22 | Critical9.8 | — | 1.7% | Oct 9, 2019 |
35Monitor | CVE-2017-20259No exploit | Joomla OSDownloads 1.7.4 SQL Injection via item viewjoomlashack · osdownloads · CWE-89 | High8.8 | — | 0.5% | Jun 19, 2026 |
- CVE-2019-1739940Plan
The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment.
CriticalCVSS 9.8No exploitEPSS 2%joomlashack · shack forms proOct 9, 2019
- CVE-2017-2025935Monitor
Joomla OSDownloads 1.7.4 SQL Injection via item view
HighCVSS 8.8No exploitEPSS 0%joomlashack · osdownloadsJun 19, 2026