See how joomlaboat compares to other vendors in security performance
Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename parameter. Attackers can send GET requests to index.php with the option=comextrasearch parameter and malicious SQL in the establename field to extract sensitive database information.
Cross-site scripting (XSS) vulnerability in includes/flvthumbnail.php in the Youtube Gallery (comyoutubegallery) component 3.4.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the videofile parameter.
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (comyoutubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.