Каталог CVE

Расширение: Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 1 461

Расширение: Joomla
Средняя CVSS 5.1

CVE-2023-54362

Разработчикdemo.virtuemart

Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attac…

09.04.2026 Активна
Средняя CVSS 5.1

CVE-2023-54361

Разработчикthethinkery

Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. At…

09.04.2026 Активна
Средняя CVSS 5.1

CVE-2023-54360

Разработчикjlexart

Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can…

09.04.2026 Активна
Критическая CVSS 9.5

CVE-2026-21627

Разработчикtassos.gr

The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functional…

20.02.2026 Требует внимания
Средняя CVSS 4.8

CVE-2026-21625

РасширениеStackideas Easydiscuss
Разработчикstackideas

User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.

16.01.2026 Активна
Критическая CVSS 9.4

CVE-2026-21624

РасширениеStackideas Easydiscuss
Разработчикstackideas

Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.

16.01.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-21623

РасширениеStackideas Easydiscuss
Разработчикstackideas

Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.

16.01.2026 Требует внимания
Средняя CVSS 5.4

CVE-2025-55758

РасширениеJDownloads
Разработчикjdownloads

Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered.

28.10.2025
Средняя CVSS 6.1

CVE-2025-55757

РасширениеVirtueMart
Разработчикgithub

A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered.

25.10.2025
Критическая CVSS 9.3

CVE-2025-40636

Разработчикincibe.es

SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retrieve database content via the ‘cip_vvisitcounter’ cookie at all endpoi…

03.10.2025
Высокая CVSS 8.5

CVE-2025-54301

РасширениеQuantum Manager
Разработчикnorrnext

A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. File names are not properly escaped.

25.08.2025
Высокая CVSS 8.5

CVE-2025-54300

РасширениеQuantum Manager
Разработчикnorrnext

A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. The SVG upload feature does not sanitize uploads.

25.08.2025
Высокая CVSS 8.7

CVE-2025-54475

Расширениеthe JS Jobs plugin versions
Разработчикgithub

A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands.

15.08.2025
Высокая CVSS 8.5

CVE-2025-54474

РасширениеDJ-Classifieds
Разработчикdj-extensions

A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.

15.08.2025
Критическая CVSS 9.2

CVE-2025-54473

РасширениеPhoca Commander
РазработчикPhoca

An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code execution via the unzip feature.

15.08.2025
Критическая CVSS 9.4

CVE-2025-54299

РасширениеNo Boss Testimonials
Разработчикnobossextensions

A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.

28.07.2025
Критическая CVSS 9.4

CVE-2025-54298

РасширениеCommentBox
Разработчикfirecoders

A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.

28.07.2025
Высокая CVSS 7.0

CVE-2025-54297

РасширениеCComment
Разработчикcompojoom

A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered.

23.07.2025