Каталог CVE

Расширение: Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 1 461

Расширение: Joomla
Высокая CVSS 7.0

CVE-2025-54296

РасширениеProFiles
Разработчикmooj

A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.

23.07.2025
Средняя CVSS 5.1

CVE-2025-54295

РасширениеDJ-Reviews
Разработчикdj-extensions

A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered.

23.07.2025
Критическая CVSS 9.3

CVE-2025-54294

РасширениеKomento
Разработчикstackideas

A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to execute arbitrary SQL commands.

23.07.2025
Высокая CVSS 8.5

CVE-2025-50127

РасширениеDJ-Flyer
Разработчикdj-extensions

A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.

23.07.2025
Средняя CVSS 5.3

CVE-2025-50126

Расширениеthe RSBlog!
Разработчикrsjoomla

A stored XSS vulnerability in the RSBlog! component 1.11.6-1.14.5 Joomla was discovered. The issue allows remote authenticated users to inject arbitrary web script or HTML via the jform[tag…

18.07.2025
Средняя CVSS 5.1

CVE-2025-50058

Расширениеthe RSDirectory!
Разработчикrsjoomla

A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the re…

18.07.2025
Средняя CVSS 6.9

CVE-2025-50057

РасширениеRSFiles!
Разработчикrsjoomla

A DOS vulnerability in RSFiles! component 1.16.3-1.17.7 Joomla was discovered. The issue allows unauthenticated remote attackers to deny access to service via the search feature.

18.07.2025
Средняя CVSS 5.1

CVE-2025-50056

РасширениеRSMail!
Разработчикrsjoomla

A reflected XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 28 Joomla was discovered. The issue allows remote attackers to inject arbitrary web script or HTML via the crafted param…

18.07.2025
Высокая CVSS 8.6

CVE-2025-49485

Расширениеthe Balbooa Forms
РазработчикНе указан в CVE

A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter.

18.07.2025
Высокая CVSS 8.7

CVE-2025-49484

Расширениеthe JS Jobs plugin versions
Разработчикgithub

A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid' parameter in the employee app…

18.07.2025
Критическая CVSS 9.8

CVE-2025-26855

РасширениеArticles Calendar
Разработчикjoomcar

A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands.

18.07.2025
Критическая CVSS 9.8

CVE-2025-26854

РасширениеArticles Good Search
Разработчикjoomcar

A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.

18.07.2025
Высокая CVSS 8.6

CVE-2025-49468

Разработчикnobossextensions

A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability allows remote authenticated users to execute arbitrary SQL commands via…

13.06.2025
Критическая CVSS 9.3

CVE-2025-49467

РасширениеJEvents component before
Разработчикjevents

A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list…

12.06.2025
Средняя CVSS 6.7

CVE-2025-32466

РасширениеRSMediaGallery!
Разработчикrsjoomla

A SQL injection vulnerability in RSMediaGallery! component 1.7.4 - 2.1.7 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properl…

11.06.2025
Высокая CVSS 8.5

CVE-2025-32465

РасширениеRSTickets!
Разработчикrsjoomla

A stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla was discovered. It allows attackers to perform cross-site scripting (XSS) attacks via sending crafted payload.

11.06.2025
Критическая CVSS 9.2

CVE-2025-30085

РасширениеRSForm!pro
Разработчикrsjoomla

Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs within the submission export feature and requires administrative acces…

11.06.2025