CVE-2018-14592: Cwjoomla Cw Article Attachments Free

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.

Affected products

  • Cwjoomla Cw Article Attachments Free: before 1.0.6 (fixed in 1.0.6)
  • Cwjoomla Cw Article Attachments Pro: before 2.0.7 (fixed in 2.0.7)

Published 2018-09-20. Last modified 2026-06-17.