See how facileforms compares to other vendors in security performance
Cross-site scripting (XSS) vulnerability in the Facileforms (comfacileforms) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter to index.php.
Cross-site scripting (XSS) vulnerability in FacileForms before 1.4.7 for Mambo and Joomla!, when either registerglobals or RGEMULATION is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.