CVE-2025-49468: Nobossextensions.com No Boss Calendar Component For Joomla

High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.

A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability allows remote authenticated users to execute arbitrary SQL commands via the id_module parameter.

Affected products

Published 2025-06-13. Last modified 2026-06-17.