CVE-2025-54475: Extension - joomsky.com - SQL injection in JS jobs component version 1.3.2 - 1.4.4 for Joomla
Published Aug 15, 2025
·Updated
A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands.
Affected Software
1 affected component
joomsky JS Jobs>=1.3.2<=1.4.4
Event History
Aug 15, 2025
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-54475?
CVE-2025-54475 is considered a high severity SQL injection vulnerability that allows low-privilege users to execute arbitrary SQL commands.
2
Who is affected by CVE-2025-54475?
CVE-2025-54475 affects versions 1.3.2 to 1.4.4 of the JS Jobs plugin for Joomla.
3
How do I fix CVE-2025-54475?
To fix CVE-2025-54475, update the JS Jobs plugin to a version above 1.4.4.
4
What types of attacks can CVE-2025-54475 enable?
CVE-2025-54475 can enable attackers to perform unauthorized SQL commands to manipulate or access database information.
5
When was CVE-2025-54475 disclosed?
CVE-2025-54475 was disclosed in 2025 and affects certain releases of Joomla's JS Jobs plugin.