CVE-2018-5975: Thekrotek Smart Shoutbox

Critical severity, CVSS 9.8. EPSS: 2.7% chance of exploitation in the next 30 days.

SQL Injection exists in the Smart Shoutbox 3.0.0 component for Joomla! via the shoutauthor parameter to the archive URI.

Affected products

Published 2018-02-17. Last modified 2026-06-17.