Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Zh Yandexmap Project Subscribe
Filtered by product Zh Yandexmap
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-6604 1 Zh Yandexmap Project 1 Zh Yandexmap 2018-02-28 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetails request.
CVE-2017-15966 1 Zh Yandexmap Project 1 Zh Yandexmap 2017-11-17 7.5 HIGH 9.8 CRITICAL
The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php.