CVE-2025-49467: Jevents.net / Gwe Systems Ltd Jevents Component For Joomla
Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.
Affected products
- Jevents.net / Gwe Systems Ltd Jevents Component For Joomla: version 1.0.0-3.6.82 only; version 3.6.83-3.6.87 only
Published 2025-06-12. Last modified 2026-06-17.