← Vulnerability feed

Vulnerability record · CVE-2015-7858 · published 29 October 2015

CVE-2015-7858: Joomla! core SQL injection allows arbitrary SQL execution

Joomla · Joomla\!

Joomla! 3.2 before 3.4.4 contains a SQL injection flaw distinct from CVE-2015-7297, allowing remote attackers to run arbitrary SQL commands through unspecified vectors. Because Joomla! is widely deployed and the flaw is remotely reachable without authentication, it is a serious risk to unpatched sites.

7.5 CVSS 2.0 High EPSS 86% · top 0.3% CWE-89 · SQL injection
7.5CVSS 2.0 base score
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7297.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote, unauthenticated SQL injection in a widely deployed CMS with public exploit code and very high EPSS, though not in KEV.

What it is

Joomla! 3.2 before 3.4.4 contains a SQL injection flaw distinct from CVE-2015-7297, allowing remote attackers to run arbitrary SQL commands through unspecified vectors. Because Joomla! is widely deployed and the flaw is remotely reachable without authentication, it is a serious risk to unpatched sites.

Impact

An attacker can read or modify database contents and, per public exploit write-ups, chain the injection to full administrative access and remote code execution.

Attack surface

Reached over the network via HTTP against the Joomla! core; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The exact vulnerable parameter is not specified in the record.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.85557, 99.7th percentile) and public exploit code exists (Exploit-DB 38797, Rapid7 module, Trustwave blog tagged Exploit), indicating active exploitation is likely.

What to do

  • Upgrade Joomla! to 3.4.4 or later immediately; this is the vendor fix.
  • If immediate upgrade is impossible, restrict or block access to the affected Joomla! endpoints at the WAF or reverse proxy.
  • Audit the Joomla! database and admin accounts for unauthorized changes or added administrator users.
  • Rotate Joomla! administrator credentials and any secrets stored in the site configuration after patching.
  • Monitor Joomla! release notes and apply future core security updates promptly.

Detection

  • Review web server logs for SQL injection patterns (UNION, SLEEP, BENCHMARK, quote-heavy payloads) against Joomla! paths.
  • Alert on unexpected creation of Joomla! administrator accounts or privilege changes in the users table.
  • Monitor for outbound connections or file writes consistent with post-exploitation RCE following a SQL injection.
  • Correlate requests to Joomla! content history or com_content endpoints with anomalous database query volume.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-7858 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-10033PHPMailer isMail mailSend argument injection enables remote code executionPHPMailer before 5.2.18 fails to properly sanitize the Sender property in the mailSend function of the isMail transport, allowing a crafted backslash…KEVEPSS 100%analysed5.3CVE-2023-23752Joomla! webservice endpoints improper access checkJoomla! 4.0.0 through 4.2.7 contains an improper access check that allows unauthenticated access to webservice endpoints. Because the endpoints can e…KEVEPSS 100%analysed9.8CVE-2026-48902Joomla\! cleartext transmission vulnerabilityThe password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.EPSS 0.33%9.8CVE-2025-25226Joomla\! sql injection vulnerabilityImproper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected …EPSS 0.47%9.8CVE-2022-23795Joomla\! improper authentication vulnerabilityAn issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which …EPSS 1.1%9.8CVE-2022-23797Joomla\! sql injection vulnerabilityAn issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted …EPSS 1.1%9.8CVE-2022-23799Joomla\! vulnerabilityAn issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.EPSS 1.2%9.8CVE-2010-1433Joomla\! unrestricted file upload vulnerabilityJoomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied in…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2015-7858), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.