CVE-2018-6008: Joomlatag Jtag Members Directory

High severity, CVSS 7.5. EPSS: 36.8% chance of exploitation in the next 30 days.

Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter.

Affected products

  • Joomlatag Jtag Members Directory: version 5.3.7 only

Published 2018-01-29. Last modified 2026-06-17.