CVE-2025-49467

All FrameworksJoomlaCWE-89CVE-2025-49467

CVE-2025-49467

State: PUBLISHED · Published: 2025-06-12 · Updated: 2025-06-12 · Assigner: Joomla
Description
A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2025/49xxx/CVE-2025-49467.json