CVE-2025-49467: Jevents.net / Gwe Systems Ltd Jevents Component For Joomla

Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.

Affected products

Published 2025-06-12. Last modified 2026-06-17.