← Vulnerability feed

Vulnerability record · CVE-2018-7318 · published 22 February 2018

CVE-2018-7318: Belitsoft checklist sql injection vulnerability

Belitsoft · Checklist

SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order parameter.

9.8 CVSS 3.1 Critical EPSS 8.7% · top 5.1% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
8.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order parameter.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://exploit-db.com/exploits/44163 ExploitThird Party AdvisoryVDB Entry
https://www.oracle.com/security-alerts/cpujan2021.html Third Party Advisory
https://exploit-db.com/exploits/44163 ExploitThird Party AdvisoryVDB Entry
https://www.oracle.com/security-alerts/cpujan2021.html Third Party Advisory

Track CVE-2018-7318 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-47056Oracle data integrator missing authentication for critical function vulnerabilityVulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 1…EPSS 0.51%9.8CVE-2026-60999Oracle data integrator improper access control vulnerabilityVulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). The supported version that is affected is …EPSS 0.51%9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%9.8CVE-2019-17195Connect2id nimbus jose\+jwt vulnerabilityConnect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potenti…EPSS 11%9.8CVE-2018-1000613Bouncycastle bc-java vulnerabilityLegion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externall…EPSS 4.8%9.8CVE-2018-8013Apache batik deserialization of untrusted data vulnerabilityIn Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name w…EPSS 19%9.8CVE-2018-9019Dolibarr sql injection vulnerabilitySQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to…EPSS 4.0%9.8CVE-2015-8965Perforce jviews permissions and access controls vulnerabilityRogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classpath, suc…EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2018-7318), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.