• Joomla!®
    • About us
    • Joomla Home
    • What is Joomla?
    • Benefits & Features
    • Project & Leadership
    • Trademark & Licensing
    • The Joomla Foundation
    • Support us
    • Contribute
    • Sponsor
    • Partner
    • Shop
  • Download & Extend
    • Downloads
    • Extensions
    • Languages
    • Get a free site
    • Get a domain
  • Discover & Learn
    • Documentation
    • Training
    • Certification
    • Site Showcase
    • Announcements
    • Blogs
    • Magazine
  • Community & Support
    • Community Portal
    • Events
    • User Groups
    • Forum
    • Service Providers Directory
    • Volunteers Portal
    • Vulnerable Extensions List
  • Developer Resources
    • Developer Network
    • Security Centre
    • Issue Tracker
    • GitHub
    • API Documentation
    • Joomla! Framework

Joomla! Extensions Directory™

Download
Launch
  • Home
  • Browse Extensions
    • Top Rated
    • Most Reviewed
    • New
    • Recently Updated
    • Compatible with J4
    • Compatible with J5
    • Compatible with J5 (with b/c plugin)
  • Search
  • Community
    • Meet the JED Team
    • Blog
    • JED Newsletter
    • Terms of Service
    • Help Joomla!
  • Support
    • Knowledgebase
    • Sponsor Joomla!
  • Vulnerable Extensions
    • About
    • Vulnerable Extensions
    • Resolved Extensions
    • Abandoned Extensions
    • Submit a Report
    • Submit an Update
    • Submit AbandonWare
    • JSON Feed
  • Log in
  • Register
  • Home
  • Vulnerable Extensions
  • Vulnerable Extensions

Vulnerable Extensions

This category lists vulnerable extensions for which no patch is known to  exists. You are recommended to uninstall any listed here from your site. Patched extensions are moved to the Resolved category.

Filters
List of articles in category Vulnerable Extensions
Title Published Date
RSMonials,2.2 and previous,XSS (Cross Site Scripting) 11 January 2017
JMS Support Online module, 2.0.0, XSS (Cross Site Scripting) 28 December 2016
AVChat Video Chat Integration Kit, File permissions 03 December 2016
HDW Player, 3.2.1 and older 24 October 2016
Huge IT Googlemaps,1.0.9,SQL Injection 26 September 2016
aceftp,unknown version,Other 17 August 2016
Yeeditor, abandonware 06 May 2016
Easy Youtube Gallery , 1.0.2,Information Disclosure 20 April 2016
Template Monster various themes 20 April 2016
User Group FTW For Hikashop,1.1.5,Other 07 April 2016

Page 8 of 24

  • 3
  • ...
  • 5
  • 6
  • 7
  • 8
  • 9
  • ...
  • 11
  • 12
VEL Search

Vulnerable Extensions
  • SP Page Builder Pro 6.7.0, 6.7.0, Other
  • EasyStore Pro 2.0.1, , Other
  • DJ-Classifieds, , Other
  • Gridbox , 2.2, Other
  • EasyDiscuss by Stackideas,, , SQL Injection
  • JEVents, 3.6.87, SQL Injection
  • osTicky2, , Other
  • EasyShop, 1.4.1, XSS (Cross Site Scripting)
  • LivingWord, , XSS (Cross Site Scripting)
  • Plugin Creative Gallery , , SQL Injection
Resolved Extensions
  • Phoca Guestbook, , Other
  • Easy File Uploader (mod_easyfileuploader), 2.9.6, Other
  • Easy File Uploader (mod_easyfileuploader), 2.9.6, Other
  • Novarain/Tassos Framework, , SQL Injection
  • jDownloads v4.0.47, jDownloads v4.0.47, Other
  • Quantum Manager v. 3.2.0, Quantum Manager v. 3.2.0, Other
  • Convert Forms, 4.4.10, XSS (Cross Site Scripting)
  • JS Jobs, 1.4.2, SQL Injection
  • Regularlabs Sourcer, pre version 12.00, Other/RFI
  • HikaShop, 5.1.1, XSS (Cross Site Scripting)

  • Joomla! on Twitter
  • Joomla! on Facebook
  • Joomla! on YouTube
  • Joomla! on LinkedIn
  • Joomla! on Pinterest
  • Joomla! on Instagram
  • Joomla! on GitHub
  • Home
  • About
  • Community
  • Forum
  • Extensions
  • Services
  • Docs
  • Developer
  • Shop
  • Accessibility Statement
  • Privacy Policy
  • Cookie Policy
  • Sponsor Joomla! with $5
  • Help Translate
  • Report an Issue
  • Log in

© 2005 - 2026 Open Source Matters, Inc. All Rights Reserved.

Rochen
Joomla! Hosting by Rochen
× We have detected that you are using an ad blocker. The Joomla! Project relies on revenue from these advertisements so please consider disabling the ad blocker for this domain.