CVE-2018-25327
📛 CVE Title
(no title)
Description
Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete job entries or modify component settings when administrators visit attacker-controlled pages.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- medium
- CVSS score
- 5.3 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N- Effective score
- 5.3 / 10 MEDIUM source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2018-25327
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-05-17 13:16:44 UTC
- NVD last modified
- 2026-05-18 17:28:19 UTC
- NVD CVSS v3.1
- 5.3 / 10 MEDIUM source: disclosure@vulncheck.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 1.4 / 10
- EPSS score
- 0.0002 (probability of exploitation in next 30 days)
- EPSS percentile
- 5.46% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24
NVD-assigned CWE(s):
CWE-352
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-05-25 00:10 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2018-21847 - Assigner
- VulnCheck
- Published
- May 17, 2026, 12:11:33 PM
- Updated
- May 18, 2026, 5:52:27 PM
- EUVD base score (CVSS 4.0)
-
6.9 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L - EUVD-reported EPSS
- 0.0200
- Vendors
- JoomSky
- Products
-
JS Jobs (1.2.0)
- Aliases
-
GHSA-mpvw-h4vq-pmfx
ENISA description: Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete job entries or modify component settings when administrators visit attacker-controlled pages.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (7)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://extensions.joomla.org/extension/js-jobs/ tenable:extensions.joomla.org
- https://nvd.nist.gov/vuln/detail/CVE-2018-25327 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2018-25327 tenable:www.cve.org
- https://www.exploit-db.com/exploits/44492 tenable:www.exploit-db.com
- https://www.first.org/epss/ tenable:www.first.org
- https://www.joomsky.com tenable:www.joomsky.com
- https://www.vulncheck.com/advisories/joomla-component-js-jobs-cross-site-request-forgery tenable:www.vulncheck.com
NVD-tagged references (4)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://extensions.joomla.org/extension/js-jobs/ disclosure@vulncheck.com
- https://www.exploit-db.com/exploits/44492 disclosure@vulncheck.com
- https://www.joomsky.com disclosure@vulncheck.com
- https://www.vulncheck.com/advisories/joomla-component-js-jobs-cross-site-request-forgery disclosure@vulncheck.com
Remediations (10)
-
web:cybersecuritynews.com
Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2.
2026-05-26 03:08 UTC -
web:patchapalooza.com
Microsoft Patch Tuesday vulnerability intelligence dashboard. Live CVSS scores, exploit tracking, threat analysis, and security update data from MSRC, VulnCheck, CISA KEV, and EPSS.
2026-05-26 03:08 UTC -
web:support.esri.com
BUG-000153493 - Installing ArcGIS Server Security 2022 Update 1 Patch or Update 2 Patch on ArcGIS Server 10.8.1 affects the access to existing Workflow Manager (Classic) feature services. BUG-000153438 - ArcGIS Server services folders become inaccessible in the REST endpoint if it has a dot (.) in the name and the Security patches are installed.
2026-05-26 03:08 UTC -
web:support.microsoft.com
This out-of-band update for Windows 11, version 25H2 and 24H2 (KB5085518) includes fixes and improvements. To learn more about differences between security updates, optional non-security preview updates, out-of-band (OOB) updates, and continuous innovation, see Windows monthly updates explained. For information on Windows update terminology, see the different types of Windows software updates ...
2026-05-26 03:08 UTC -
web:www.bleepingcomputer.com
Microsoft has released Windows 11 KB5079473 and KB5078883 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.
2026-05-26 03:08 UTC -
web:www.cisa.gov
Updated October 29, 2025: CISA has updated this Alert to include revised information on vulnerable product identification, potential threat activity detections, and additional resources. Microsoft released an update to address a critical remote code execution vulnerability impacting Windows Server Update Service (WSUS) in Windows Server (2012, 2016, 2019, 2022, and 2025), CVE -2025-59287
2026-05-26 03:08 UTC -
web:www.oracle.com
Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.
2026-05-26 03:08 UTC -
web:www.pcworld.com
This month's Patch Tuesday includes an actively exploited Office zero-day vulnerability and several critical RCE bugs in Windows and Remote Desktop.
2026-05-26 03:08 UTC -
web:www.windowscentral.com
Another out of band update has been issued to Windows 11 users to address a major bug that caused Outlook to become inoperable after January's disastrous Patch Tuesday updates.
2026-05-26 03:08 UTC -
web:www.windowslatest.com
Here is everything that is included in KB5077181: New features rolling out with the February 2026 Windows 11 update The February 2026 Patch Tuesday update introduces a solid set of new features ...
2026-05-26 03:08 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.