216.73.217.22

CVE-2018-25380

· Published 25/05/2026 15:16 · Modified 26/05/2026 19:47

Labels: CVE-2018-25380 2026-05-25CVE-2018-25380CWE-89[email protected]

Essential information

Published
25/05/2026 15:16
Modified
26/05/2026 19:47
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, and filter_search parameters. Attackers can submit POST requests to the extroformfield view with malicious SQL payloads to extract sensitive database information and server data.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
joomla / extroforms cpe:2.3:a:joomla:extroforms:2.1.5:*:*:*:*:*:*:*

References