See how michael dempfle compares to other vendors in security performance
Multiple PHP remote file inclusion vulnerabilities in Michael Dempfle Joomla Flash Uploader (comjfu or comjoomlaflashuploader) 2.5.1 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter to (1) install.joomlaflashuploader.php and (2) uninstall.joomlaflashuploader.php.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2024.2.