PatchSiren

Mojoomla CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Mojoomla CVE published 2026-06-17

CVE-2025-15657

CVE-2025-15657 is a MEDIUM severity vulnerability (CVSS Score: 5.3) affecting School Management plugin versions <= 93.1.0. This Unauthenticated Insecure Direct Object References (IDOR) vulnerability allows attackers to access sensitive data without authentication. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected plugin should take immediate action [truncated]