vBizz vulnerabilities
CVEs whose affected-version data names the vBizz package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2019-25759High· 7.1PoCJoomla! Component vBizz 1.0.7 SQL Injection
Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid parameter. Attackers can submit POST requests to the…
▾ MidnightWdmtech · vBizzEPSS 0.40%via CVEORG
CVE-2019-25758High· 8.8Joomla! Component vBizz 1.0.7 Remote Code Execution
Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submitting malicious files through the profile_pic parameter. Attackers can upload PHP …
▾ TwilightWdmtech · vBizzEPSS 1.0%via CVEORG