SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
extensiondeveloper questions 1.4.3