CVE-2018-17383: Thephpfactory Collection Factory
Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.
Affected products
- Thephpfactory Collection Factory: version 4.1.9 only
Published 2018-09-28. Last modified 2026-06-17.