The jNews (comjnews) component 7.5.1 for Joomla! allows remote attackers to obtain sensitive information via the emailsearch parameter, which reveals the installation path in an error message.
The JNews WordPress theme before 8.0.6 did not sanitise the catid parameter in the POST request /?ajax-request=jnews (with action=jnewsbuildmegacategory), leading to a Reflected Cross-Site Scripting (XSS) issue.