The Vinaora Visitors Counter module, version 2.0.4j3 and earlier, contains a SQL injection reachable through the cip_vvisitcounter cookie on every endpoint where the module counts a visit. No authentication is required. CVSS 9.3 (Critical). The module reports its version as plain "2.0.4" in the Joomla manifest, so the ceiling here is 2.0.4 inclusive. Update to 3.4.0 or later, or remove the module - the extension is no longer actively maintained.
The base metrics as INCIBE CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.
Updating for CVE-2025-40636 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.
CVE-2025-40636 affects Visitors Counter up to and including 2.0.4.
How do I fix CVE-2025-40636?
Update Visitors Counter to 3.4.0 or later. Then confirm the installed version on the Joomla administrator's Extensions: Manage screen.
How severe is CVE-2025-40636?
INCIBE CNA scores it 9.3 (Critical) under CVSS 4.0. In plain terms: reachable across the internet, no account needed and nobody has to be tricked into anything.
Running an affected version on a site you manage?
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
We use essential cookies to run the site. With your consent we also use Google Analytics and a Meta pixel to measure and improve our marketing. See our cookie policy.