CVE-2018-5989: Chillcreations Ccnewsletter
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011-5099.
Affected products
- Chillcreations Ccnewsletter: from 2.0.0, up to and including 2.2.4
Published 2018-02-17. Last modified 2026-06-17.