Showing 2 vulnerabilities on this page for vBizz

Signals CISA KEV Ransomware Nuclei
Wdmtech vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Joomla! Component vBizz 1.0.7 SQL Injection

Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid parameter. Attackers can submit POST requests to the employee management interface with crafted payid array values containing SQL commands to extract sensitive database information including version and database names.

CWE-89Jun 19, 2026
CVSS7.1v4.0EPSS0.367%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Joomla! Component vBizz 1.0.7 Remote Code Execution

Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submitting malicious files through the profile_pic parameter. Attackers can upload PHP files via POST requests to the employee view endpoint and execute them from the uploads directory to achieve remote code execution.

CWE-434Jun 19, 2026
CVSS8.7v4.0EPSS0.952%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX