CVE-2025-49467

Publication date

2025-06-12 15:18:32

Family

Joomla

State

PUBLISHED

Description

A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.