CVE-2018-17254

CRITICAL EXPLOITED NUCLEI

JCK Editor <6.4.4 - SQL Injection

Title source: llm

Description

The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.

Exploits (5)

exploitdb WORKING POC VERIFIED
by Hamza Megahed · textwebappsphp
https://www.exploit-db.com/exploits/45423
exploitdb WORKING POC
by Nicholas Ferreira · phpwebappsphp
https://www.exploit-db.com/exploits/49627
nomisec WORKING POC 10 stars
by Nickguitar · remote
https://github.com/Nickguitar/Joomla-JCK-Editor-6.4.4-SQL-Injection
nomisec SCANNER 1 stars
by 7amzahard · poc
https://github.com/7amzahard/script-python-to-detect-CVE-2018-17254
nomisec WORKING POC
by MataKucing-OFC · remote
https://github.com/MataKucing-OFC/CVE-2018-17254

Nuclei Templates (1)

Joomla! JCK Editor SQL Injection
CRITICALby Suman_Kar

Scores

CVSS v3 9.8
EPSS 0.8523
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-09-14
CWE
CWE-89
Status published
Products (1)
arkextensions/jck_editor 6.4.4
Published Sep 20, 2018
Tracked Since Feb 18, 2026