CVE-2019-25762
Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with option=com_jpprojects&view=projects&tmpl=component&format=json parameters to retrieve user IDs, names, and email addresses in JSON format.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.63%
- CWE
- CWE-359
- Published
- 2026-06-19
- Last modified
- 2026-06-22
Affected products
- Joomboost JoomProject
Weakness type
Related vulnerabilities
- CVE-2026-73008 — Windows Biometric Service Information Disclosure Vulnerability
- CVE-2026-69351 — Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability
- CVE-2026-21827 — HCL Connections is vulnerable to an information disclosure vulnerability
- CVE-2026-53497 — CrossWatch: Unauthenticated /api/app-auth/status endpoint leaks active session metadata (IP, User-Agent, session IDs)
- CVE-2026-58510 — GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- CVE-2026-48048 — XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests
- CVE-2026-24078 — Exposure of Private Personal Information to an Unauthorized Actor in Data Modem
- CVE-2026-55496 — Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicate