Text Exploits

31,346 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-17394 EXPLOITDB CRITICAL text
Joomla! Timetable Schedule <3.6.8 - SQL Injection
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17384 EXPLOITDB CRITICAL text VERIFIED
Swap Factory 2.2.1 - SQL Injection
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17385 EXPLOITDB CRITICAL text VERIFIED
Social Factory 3.8.3 - SQL Injection
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17376 EXPLOITDB CRITICAL text VERIFIED
Joomla! Reverse Auction Factory 4.3.8 - SQL Injection
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
by Ihsan Sencan
CVSS 9.8
EIP-2026-108847 EXPLOITDB text
Joomla! Component Responsive Portfolio 1.6.1 - 'filter_order_Dir' SQL Injection
by AkkuS
CVE-2018-17379 EXPLOITDB CRITICAL text VERIFIED
Raffle Factory 3.5.2 - SQL Injection
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17377 EXPLOITDB CRITICAL text
Joomla! 1.4.3 - SQL Injection
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17378 EXPLOITDB CRITICAL text VERIFIED
Penny Auction Factory 2.0.4 - SQL Injection
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17375 EXPLOITDB CRITICAL text VERIFIED
Music Collection 3.0.3 - SQL Injection
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17382 EXPLOITDB CRITICAL text VERIFIED
Jobs Factory 2.0.4 - SQL Injection
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
by Ihsan Sencan
CVSS 9.8
EIP-2026-108646 EXPLOITDB text
Joomla! Component eXtroForms 2.1.5 - 'filter_type_id' SQL Injection
by AkkuS
CVE-2018-17383 EXPLOITDB CRITICAL text
Joomla! - SQL Injection
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17380 EXPLOITDB CRITICAL text VERIFIED
Article Factory Manager 4.3.9 - SQL Injection
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17397 EXPLOITDB CRITICAL text
AlphaIndex Dictionaries <1.0 - SQL Injection
SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
by Ihsan Sencan
CVSS 9.8
EIP-2026-101953 EXPLOITDB text
RICOH MP C6503 Plus Printer - Cross-Site Scripting
by Ismail Tasdelen
EIP-2026-101951 EXPLOITDB text
RICOH MP C406Z Printer - Cross-Site Scripting
by Ismail Tasdelen
EIP-2026-101950 EXPLOITDB text
RICOH MP C2003 Printer - Cross-Site Scripting
by Ismail Tasdelen
EIP-2026-101949 EXPLOITDB text
RICOH MP 305+ Printer - Cross-Site Scripting
by Ismail Tasdelen
CVE-2018-17374 EXPLOITDB CRITICAL text
Auction Factory 4.5.5 - SQL Injection
SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17386 EXPLOITDB CRITICAL text
Micro Deal Factory 2.4.0 - SQL Injection
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17255 EXPLOITDB text
Rejected
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-14014. Reason: This candidate is a reservation duplicate of CVE-2020-14014. Notes: All CVE users should reference CVE-2020-14014 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
by Renzi
CVE-2018-17128 EXPLOITDB MEDIUM text
MyBB <1.8.19 - XSS
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
by Numan OZDEMIR
CVSS 5.4
CVE-2018-14592 EXPLOITDB CRITICAL text
CWJoomla <2.0.7, <1.0.6 - SQL Injection
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.
by Haboob Team
CVSS 9.8
EIP-2026-102752 EXPLOITDB text
udisks2 2.8.0 - Denial of Service (PoC)
by Marshall Whittaker
EIP-2026-101952 EXPLOITDB text
RICOH MP C6003 Printer - Cross-Site Scripting
by Ismail Tasdelen