Filtered by vendor Jdownloads Subscriptions
Total 7 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-55758 2 Jdownloads, Joomla 3 Jdownloads, Joomla, Joomla! 2025-10-30 5.4 Medium
Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered.
CVE-2022-27909 1 Jdownloads 1 Jdownloads 2024-11-21 4.3 Medium
In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files
CVE-2020-19455 1 Jdownloads 1 Jdownloads 2024-11-21 7.5 High
SQL injection exists in the jdownloads 3.2.63 component for Joomla! via components/com_jdownloads/helpers/categories.php, order function via the filter_order parameter.
CVE-2020-19451 1 Jdownloads 1 Jdownloads 2024-11-21 7.5 High
SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, updateLog function via the X-forwarded-for Header parameter.
CVE-2020-19450 1 Jdownloads 1 Jdownloads 2024-11-21 7.5 High
SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, getUserLimits function in the list parameter.
CVE-2020-19447 1 Jdownloads 1 Jdownloads 2024-11-21 7.5 High
SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_files_id parameter.
CVE-2018-10068 1 Jdownloads 1 Jdownloads 2024-11-21 N/A
The jDownloads extension before 3.2.59 for Joomla! has XSS.