SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request.
- https://www.exploit-db.com/exploits/43860/
- https://github.com/ARPSyndicate/cvemon