See how ijoomla compares to other vendors in security performance
The iJoomla comadagency plugin 6.0.9 for Joomla! allows SQL injection via the advertiserstatus and statusselect parameters to index.php.
PHP remote file inclusion vulnerability in iJoomla Magazine (commagazine) component 3.0.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the config parameter to magazine.functions.php.
SQL injection vulnerability in the iJoomla RSS Feeder (comijoomlarss) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in an xml action to index.php.
Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to private information and components, possibility to view other users' information. Information disclosure Access to private information and components, possibility to view other users' information.
Directory traversal vulnerability in the iJoomla News Portal (comnewsportal) component 1.5.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.