NA - CVE-2025-49485 - A SQL injection vulnerability in the Balbooa...
A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter.
NA - CVE-2025-50056 - A reflected XSS vulnerability in RSMail!...
A reflected XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 28 Joomla was discovered. The issue allows remote attackers to inject arbitrary web script or HTML via the crafted parameter.
NA - CVE-2025-50057 - A DOS vulnerability in RSFiles! component...
A DOS vulnerability in RSFiles! component 1.16.3-1.17.7 Joomla was discovered. The issue allows unauthenticated remote attackers to deny access to service via the search feature.
NA - CVE-2025-50058 - A stored XSS vulnerability in the RSDirectory!...
A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review...
NA - CVE-2025-50126 - A stored XSS vulnerability in the RSBlog!...
A stored XSS vulnerability in the RSBlog! component 1.11.6-1.14.5 Joomla was discovered. The issue allows remote authenticated users to inject arbitrary web script or HTML via the jform[tags_text]...