Skip to content

rolandd.com vulnerabilities

3 CVEs tracked

The 'RO CSVI' Joomla extension by rolandd.com is highlighted in our reports with multiple critical vulnerabilities. The main issues identified are unauthenticated directory creation (CVE-2026-65943), CSRF (CVE-2026-65944), and XSS (CVE-2026-65946) vectors within its AJAX endpoint handlers. All these vulnerabilities affect versions prior to 9.11.0. Defenders should prioritize immediately updating the RO CSVI extension to the latest version.

Azərbaycanca: rolandd.com-un "RO CSVI" Joomla uzantısı hesabatlarımızda çoxsaylı kritik zəifliklərlə bağlı diqqət mərkəzindədir. Aşkar edilmiş əsas problemlər AJAX endpoint handler-lərində autentifikasiya olunmamış kataloq yaratma (CVE-2026-65943), CSRF (CVE-2026-65944) və XSS (CVE-2026-65946) vektorlarıdır. Bütün bu zəifliklər 9.11.0 versiyasından əvvəlki versiyalara təsir edir. Müdafiəçilər RO CSVI uzantısının dərhal ən son versiyaya yenilənməsini prioritetləşdirməlidirlər.

This vendor's CVEs3

This hub is built from skopnix's own reporting on rolandd.com: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.