Joomla! Core is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Joomla! Core versions 3.x.x ranging from 3.0.0 and up to and including 3.4.6 are vulnerable.
Update to Joomla! Core version 3.4.7 or latest
WordPress Plugin Easy Social Feed-Social Photos Gallery-Post Feed-Like Box Cross-Site Scripting (4.4.1)
WordPress Plugin Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Multiple Cross-Site Scripting Vulnerabilities (3.9.8)
WordPress Plugin AccessPress Custom CSS includes Backdoor [Only if downloaded via the vendor website] (2.0.1)
WordPress Plugin Student Result or Employee Database Security Bypass (1.6.3)
WordPress Plugin FireStorm Professional Real Estate 'id' Parameter SQL Injection (2.06.03)