CVE Database
/

CVE-2025-49467

Back to search

CVE-2025-49467

Published: Jun 12, 2025

Modified: Jun 12, 2025

PUBLISHED

Description

A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.

VendorProductVersions

jevents.net / GWE Systems Ltd

JEvents component for Joomla

affected
1.0.0-3.6.82
unaffected
3.6.82.1
affected
3.6.83-3.6.87

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now