Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure
User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.