Aggregates CVE and security vulnerability intelligence across all joomlacalendars-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk sql injection and vendor risk path handling and related problems; some flaws may lead to vendor impact data exposure, affecting vendor surface software deployment scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2018-6398 | SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action. | [email protected] | 9.8 | 2.70% | 2018-01-30 | 2026-06-16 |
| CVE-2018-6397 | Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter. | [email protected] | 7.5 | 12.17% | 2018-01-30 | 2026-06-16 |
| CVE-2018-6395 | SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action. | [email protected] | 9.8 | 2.70% | 2018-01-30 | 2026-06-16 |