Custom PHP Pages
http://extensions.joomla.org/extensions/edition/custom-code-in-content/5057 LFI Vulnerability Developer declares not vulnerable 140510
FDione Form Wizard
lfi vulnerability 140510 200510 Update to Dione Form Wizard (v. 1.0.4).
Seber Cart
Local File Disclosure Vulnerability Developer Update 140510
konsultasi
SQL Injection Vulnerability
JE Quotation Form
http://joomlaextensions.co.in/free-download/doc_download/11-je-quotation-form.html LFI
SimpleDownload
http://extensions.joomla.org/extensions/directory-a-documentation/downloads/10717 various exploits 160510 updated version (version 0.9.6)
BCA RSS Feed
LFI and other vulnerabilities Upgrade to Ninja RSS Syndicator 1.0.9 or later
RS Comments
XSS Vulnerability – fix posted 210510
ActiveHelper LiveHelp
XSS in LiveHelp 200510
SectionEx
Stack Ideas section Ex LFI