CVE-2018-10063: Convert Forms Project Convert Forms

High severity, CVSS 7.8. EPSS: 9.1% chance of exploitation in the next 30 days.

The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that is mishandled when exporting a Leads file.

Affected products

Published 2018-04-12. Last modified 2026-06-17.