stackideas CVE Vulnerabilities & CVE List (9)

Products (CPE): — CVEs: 9

stackideas vulnerability overview

Aggregates CVE and security vulnerability intelligence across all stackideas-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting, vendor risk sql injection, and vendor risk path handling, with potential vendor impact session compromise across vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 19 of 9 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-21626 Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure [email protected] 9.2 0.02% 2026-02-06 2026-02-18
CVE-2026-21625 User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening. [email protected] 4.8 0.02% 2026-01-16 2026-01-30
CVE-2026-21624 Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla. [email protected] 9.4 0.03% 2026-01-16 2026-01-30
CVE-2026-21623 Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla. [email protected] 9.4 0.03% 2026-01-16 2026-01-30
CVE-2023-51810 SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the search parameter in the Users module. [email protected] 7.5 6.18% 2024-01-16 2025-06-20
CVE-2018-5263 The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS. [email protected] 5.4 0.23% 2018-01-08 2024-11-21
CVE-2015-7324 Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) img or (2) url tag of a new comment. [email protected] 6.1 0.32% 2017-12-27 2026-05-13
CVE-2014-1837 Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors related to "checking new comments." [email protected] 4.3 0.37% 2014-01-30 2026-04-29
CVE-2014-0793 Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website or (2) latitude parameter in a comment to the default URI. [email protected] 4.3 0.73% 2014-01-30 2026-04-29
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence