Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchword parameter to extract sensitive database information.
History

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Joomshaper standard Pro Movie Database
CPEs cpe:2.3:a:joomshaper:standard_pro_movie_database:1.3:*:*:*:*:joomal\!:*:*
Vendors & Products Joomshaper standard Pro Movie Database

Mon, 22 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 21 Jun 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Joomshaper
Joomshaper sp Movie Database
Vendors & Products Joomshaper
Joomshaper sp Movie Database

Fri, 19 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Description Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchword parameter to extract sensitive database information.
Title Joomla SP Movie Database 1.3 SQL Injection via searchword
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-06-19T16:04:28.631Z

Updated: 2026-06-22T19:39:00.953Z

Reserved: 2026-06-19T15:05:05.309Z

Link: CVE-2017-20266

cve-icon Vulnrichment

Updated: 2026-06-22T19:38:56.744Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-19T16:16:16.427

Modified: 2026-08-19T16:22:06.123

Link: CVE-2017-20266

cve-icon Redhat

No data.