CVE-2017-15966: Zh Yandexmap Project Zh Yandexmap

Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.

The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php.

Affected products

Published 2017-10-29. Last modified 2026-06-17.