CVE-2015-7857: Joomla!
High severity, CVSS 7.5. EPSS: 94.5% chance of exploitation in the next 30 days.
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arbitrary SQL commands via the list[select] parameter to index.php.
Affected products
- Joomla! Joomla!: version 3.2.0 only; version 3.2.1 only; version 3.2.2 only; version 3.2.3 only; version 3.2.4 only; version 3.3.0 only; …
Published 2015-10-29. Last modified 2026-06-17.