Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index

JEvents security vulnerabilities

mySites.guru tracks 2 vulnerabilities in com_jevents. Every connected Joomla site is checked against them on each audit, and flagged if it runs an affected version.

What we check for

CriticalCVE-2025-49467CVE-2015-73402025-01-01

JEvents (com_jevents) 1.0.0 to 3.6.82 - CVE-2025-49467 (CVSS 9.3) Unauthenticated SQL Injection

JEvents versions 1.0.0 through 3.6.82 are vulnerable to unauthenticated SQL injection via publicly accessible actions that list events by date ranges (CVE-2025-49467, CVSS 4.0 9.3 Critical). No login is required. Fixed in 3.6.88; the vendor also released 3.6.82.1 as a backport hotfix for the 3.6.82 line, which is NOT affected. Update to 3.6.88 or later (or 3.6.82.1 if staying on the older line). Also within this rule: CVE-2015-7340 (JEvents below 3.4.0), which sits below this ceiling and needs no separate row.

Affected versions: ≤ 3.6.82

Full advisory: ccb.belgium.be

JEvents (com_jevents) 3.6.83 to 3.6.87 - CVE-2025-49467 (CVSS 9.3) Unauthenticated SQL Injection

JEvents versions 3.6.83 through 3.6.87 are vulnerable to unauthenticated SQL injection via publicly accessible actions that list events by date ranges (CVE-2025-49467, CVSS 4.0 9.3 Critical). No login is required. These releases shipped without the fix that was backported to 3.6.82.1; the fix is in 3.6.88. Update to 3.6.88 or later.

Affected versions: ≥ 3.6.83 and ≤ 3.6.87

Full advisory: www.cve.org

Running JEvents on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

CVE identifiers: CVE-2025-49467, CVE-2015-7340. Rules current as of 13 September 2026.