Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

joomunited — Vulnerabilities & Security Advisories 24

Browse all 24 CVE security advisories affecting joomunited. AI-powered Chinese analysis, POCs, and references for each vulnerability.

JoomUnited operates as a developer of extensions for the Joomla content management system, providing tools for e-commerce, booking, and social networking. Security audits have identified twenty distinct Common Vulnerabilities and Exposures (CVEs) associated with its software portfolio, indicating a persistent history of security flaws. The most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from insufficient input validation and improper access controls. Several incidents highlight critical privilege escalation risks, allowing unauthenticated attackers to gain administrative access or execute arbitrary code on affected servers. These issues frequently arise in older versions of popular plugins, emphasizing the necessity for rigorous code review and timely patching. The accumulation of these CVEs suggests that while the extensions offer functional utility, their security posture has been inconsistent, requiring users to prioritize version updates and configuration hardening to mitigate potential exploitation vectors.

Found 13 results / 24Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-9643 WP Meta SEO <= 4.5.18 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI in 404 Logging — WP Meta SEOCWE-79 7.2 High2026-06-24
CVE-2026-11370 WP Meta SEO <= 4.5.18 - Authenticated (Contributor+) Server-Side Request Forgery via 'new_link' Parameter — WP Meta SEOCWE-918 6.4 Medium2026-06-24
CVE-2024-45455 WordPress WP Meta SEO plugin <= 4.5.13 - Cross Site Scripting (XSS) vulnerability — WP Meta SEOCWE-79 5.9 Medium2024-09-15
CVE-2024-45456 WordPress WP Meta SEO plugin <= 4.5.13 - Cross Site Scripting (XSS) vulnerability — WP Meta SEOCWE-79 6.5 Medium2024-09-15
CVE-2023-6961 WP Meta SEO <= 4.5.12 - Unauthenticated Stored Cross-Site Scripting via Referer header — WP Meta SEOCWE-79 7.2 High2024-05-02
CVE-2023-6962 WP Meta SEO <= 4.5.12 - Information Exposure via Meta Description — WP Meta SEOCWE-1230 5.3 Medium2024-05-02
CVE-2023-1022 WP Meta SEO <= 4.5.3 - Missing Authorization in 'wpmsGGSaveInformation' — WP Meta SEOCWE-862 5.4 Medium2023-02-28
CVE-2023-1023 WP Meta SEO <= 4.5.3 - Missing Authorization in 'saveSitemapSettings' — WP Meta SEOCWE-862 5.4 Medium2023-02-28
CVE-2023-1024 WP Meta SEO <= 4.5.3 - Missing Authorization in 'regenerateSitemaps' — WP Meta SEOCWE-862 4.3 Medium2023-02-28
CVE-2023-1026 WP Meta SEO <= 4.5.3 - Missing Authorization in 'listPostsCategory' — WP Meta SEOCWE-862 4.3 Medium2023-02-28
CVE-2023-1027 WP Meta SEO <= 4.5.3 - Missing Authorization in 'checkAllCategoryInSitemap' — WP Meta SEOCWE-862 4.3 Medium2023-02-28
CVE-2023-1028 WP Meta SEO <= 4.5.3 - Cross-Site Request Forgery via 'setIgnore' — WP Meta SEOCWE-352 4.3 Medium2023-02-28
CVE-2023-1029 WP Meta SEO <= 4.5.3 - Cross-Site Request Forgery via 'regenerateSitemaps' — WP Meta SEOCWE-352 4.3 Medium2023-02-24

This page lists every published CVE security advisory associated with joomunited. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.