Joomla Komento Component SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in the Komento component for Joomla, specifically in versions 4.0.0 through 4.0.7. This vulnerability allows unprivileged users to execute arbitrary SQL commands.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of SQL commands, potentially allowing attackers to manipulate the database or access sensitive information.

Added: Jul 23, 2025, 12:19 PM
Updated: Jul 23, 2025, 12:19 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
5.0
exploitability
7.6
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.