CVE-2018-5989: Chillcreations Ccnewsletter

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011-5099.

Affected products

Published 2018-02-17. Last modified 2026-06-17.