JEvents (com_jevents) 1.0.0 to 3.6.82 - CVE-2025-49467 (CVSS 9.3) Unauthenticated SQL Injection
JEvents versions 1.0.0 through 3.6.82 are vulnerable to unauthenticated SQL injection via publicly accessible actions that list events by date ranges (CVE-2025-49467, CVSS 4.0 9.3 Critical). No login is required. Fixed in 3.6.88; the vendor also released 3.6.82.1 as a backport hotfix for the 3.6.82 line, which is NOT affected. Update to 3.6.88 or later (or 3.6.82.1 if staying on the older line). Also within this rule: CVE-2015-7340 (JEvents below 3.4.0), which sits below this ceiling and needs no separate row.
Affected versions: ≤ 3.6.82
Full advisory: ccb.belgium.be