Skip to content

CVE-2014-4960

Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0081 (0.8%)
Percentile: 74.2%
EPSS: 2026-05-06

Affects

joomlaboat:com_youtubegallery

Technical description

Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.

Published: 7/21/2014, 2:55:06 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam