← Back

Joommasters

joommasters

6 CVEs • 6 products

Products (6)

Click to collapse
Toggle
Jms Music
jms_music
Jms Blog
jms_blog
Jms Slider
jms_slider
Jmspagebuilder
jmspagebuilder
Jmssetting
jmssetting

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Joommasters
1Jmssetting
Jun 17, 2026
Jan 19, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0. The method `JmsSetting::getSecondImgs()` has a sensitive SQL call that can be executed wit...Show more
In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0. The method `JmsSetting::getSecondImgs()` has a sensitive SQL call that can be executed with a trivial http call and exploited to forge a blind SQL injection.Show less
1Joommasters
1Jmspagebuilder
Jun 17, 2026
Jun 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php.
1Joommasters
1Jms Slider
Jun 17, 2026
Jun 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php.
1Joommasters
1Jms Drop Mega Menu
Jun 17, 2026
Jun 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php.
1Joommasters
1Jms Blog
Jun 17, 2026
Mar 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.
1Joommasters
1Jms Music
Jun 17, 2026
Feb 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter.