Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2017-20267 1 Joomlathat 1 Calendar Planner 2026-06-20 8.2 High
Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET requests to the events view with malicious SQL code in the category_id parameter to extract sensitive database information.
CVE-2018-17375 1 Joomlathat 1 Music Collection 2024-11-21 N/A
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.