stackideas records
9 published records for vendor stackideas.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2026-21623No exploit | Extension - stackideas.com - Persistent XSS in EasyDiscuss component 1.0.0-5.0.15 for Joomlastackideas · easydiscuss · CWE-79 | Critical9.4 | — | 0.2% | Jan 16, 2026 |
37Monitor | CVE-2026-21624No exploit | Extension - stackideas.com - Persistent XSS in EasyDiscuss component 1.0.0-5.0.15 for Joomlastackideas · easydiscuss · CWE-79 | Critical9.4 | — | 0.2% | Jan 16, 2026 |
36Monitor | CVE-2026-21626No exploit | Extension - stackideas.com - Information disclosure in post custom fields in EasyDiscuss 1.0.0-5.0.15 for Joomlastackideas · easydiscuss · CWE-200 | Critical9.2 | — | 0.4% | Feb 6, 2026 |
30Monitor | CVE-2023-51810Proof of concept | SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive informationstackideas · easydiscuss · CWE-89 | High7.5 | — | 1.1% | Jan 15, 2024 |
25Monitor | CVE-2015-7324No exploit | Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 fostackideas · komento · CWE-79 | Medium6.1 | — | 1.8% | Dec 27, 2017 |
21Monitor | CVE-2018-5263Proof of concept | The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.stackideas · easydiscuss · CWE-79 | Medium5.4 | — | 1.6% | Jan 8, 2018 |
19Monitor | CVE-2026-21625No exploit | Extension - stackideas.com - Lack of mime type validation in EasyDiscuss component 1.0.0-5.0.15 for Joomlastackideas · easydiscuss · CWE-434 | Medium4.8 | — | 0.4% | Jan 16, 2026 |
18Monitor | CVE-2014-0793Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for Joomla! allow remote stackideas · komento · CWE-79 | Medium4.3 | — | 1.7% | Jan 30, 2014 |
17Monitor | CVE-2014-1837No exploit | Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla! allows remote attackers stackideas · komento · CWE-79 | Medium4.3 | — | 1.2% | Jan 30, 2014 |
- CVE-2026-2162337Monitor
Extension - stackideas.com - Persistent XSS in EasyDiscuss component 1.0.0-5.0.15 for Joomla
CriticalCVSS 9.4No exploitEPSS 0%stackideas · easydiscussJan 16, 2026
- CVE-2026-2162437Monitor
Extension - stackideas.com - Persistent XSS in EasyDiscuss component 1.0.0-5.0.15 for Joomla
CriticalCVSS 9.4No exploitEPSS 0%stackideas · easydiscussJan 16, 2026
- CVE-2026-2162636Monitor
Extension - stackideas.com - Information disclosure in post custom fields in EasyDiscuss 1.0.0-5.0.15 for Joomla
CriticalCVSS 9.2No exploitEPSS 0%stackideas · easydiscussFeb 6, 2026
- CVE-2023-5181030Monitor
SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information
HighCVSS 7.5Proof of conceptEPSS 1%stackideas · easydiscussJan 15, 2024
- CVE-2015-732425Monitor
Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 fo
MediumCVSS 6.1No exploitEPSS 2%stackideas · komentoDec 27, 2017
- CVE-2018-526321Monitor
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
MediumCVSS 5.4Proof of conceptEPSS 2%stackideas · easydiscussJan 8, 2018
- CVE-2026-2162519Monitor
Extension - stackideas.com - Lack of mime type validation in EasyDiscuss component 1.0.0-5.0.15 for Joomla
MediumCVSS 4.8No exploitEPSS 0%stackideas · easydiscussJan 16, 2026
- CVE-2014-079318Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for Joomla! allow remote
MediumCVSS 4.3Proof of conceptEPSS 2%stackideas · komentoJan 30, 2014
- CVE-2014-183717Monitor
Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla! allows remote attackers
MediumCVSS 4.3No exploitEPSS 1%stackideas · komentoJan 30, 2014