Aggregates CVE and security vulnerability intelligence across all joommasters-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Common weakness patterns include vendor risk sql injection, with potential vendor impact data exposure across vendor surface production workloads and vendor surface software deployment use cases.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-50030 | In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0. The method `JmsSetting::getSecondImgs()` has a sensitive SQL call that can be executed with a trivial http call and exploited to forge a blind SQL injection. | [email protected] | 9.8 | 0.67% | 2024-01-19 | 2026-06-17 |
| CVE-2023-29632 | PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php. | [email protected] | 9.8 | 1.03% | 2023-06-06 | 2026-06-17 |
| CVE-2023-29631 | PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php. | [email protected] | 9.8 | 0.67% | 2023-06-05 | 2026-06-17 |
| CVE-2023-29630 | PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php. | [email protected] | 9.8 | 1.03% | 2023-06-05 | 2026-06-17 |
| CVE-2023-27034 | PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability. | [email protected] | 9.8 | 58.74% | 2023-03-23 | 2026-06-17 |
| CVE-2018-6581 | SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter. | [email protected] | 9.8 | 2.70% | 2018-02-02 | 2026-06-16 |