Каталог CVE

Расширение: Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 1 461

Расширение: Joomla
Высокая CVSS 7.1

CVE-2019-25740

Разработчикexploit-db

Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send…

04.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2018-25433

Разработчикjoomlaextensions.co.in

Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through t…

01.06.2026 Требует внимания
Высокая CVSS 7.1

CVE-2018-25381

Разработчикextro.media

Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers…

25.05.2026 Требует внимания
Высокая CVSS 7.1

CVE-2018-25380

Разработчикextro.media

Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, an…

25.05.2026 Требует внимания
Средняя CVSS 5.3

CVE-2018-25354

Разработчикexploit-db

Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authenticated users into visiting mal…

23.05.2026 Активна
Высокая CVSS 8.8

CVE-2018-25351

Разработчикexploit-db

Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into t…

23.05.2026 Требует внимания
Высокая CVSS 8.8

CVE-2018-25348

Разработчикexploit-db

Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter…

23.05.2026 Требует внимания
Средняя CVSS 5.3

CVE-2018-25337

Разработчикexploit-db

Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicio…

17.05.2026 Активна
Высокая CVSS 8.8

CVE-2018-25330

Разработчикexploit-db

Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST para…

17.05.2026 Требует внимания
Средняя CVSS 6.9

CVE-2018-25327

Разработчикexploit-db

Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft mal…

17.05.2026 Активна
Высокая CVSS 7.1

CVE-2020-37226

Разработчикjoomsky

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' para…

13.05.2026 Требует внимания
Высокая CVSS 7.1

CVE-2020-37224

Разработчикjoomsky

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' para…

13.05.2026 Требует внимания
Высокая CVSS 8.7

CVE-2020-37219

Разработчикfabrikar

Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send…

13.05.2026 Требует внимания
Высокая CVSS 8.8

CVE-2020-37218

Разработчикexploit-db

Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code th…

13.05.2026 Требует внимания
Высокая CVSS 8.8

CVE-2021-47930

Разработчикbalbooa

Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Atta…

10.05.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-34424

Разработчикpatchstack

Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers…

09.04.2026 Требует внимания
Средняя CVSS 5.1

CVE-2023-54364

Разработчикdemo.hikashop

Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product…

09.04.2026 Активна
Средняя CVSS 5.1

CVE-2023-54363

Разработчикsolidres

Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters incl…

09.04.2026 Активна