Каталог CVE

Расширение: Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 1 461

Расширение: Joomla
Высокая CVSS 7.5

CVE-2020-35611

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.

28.12.2020
Высокая CVSS 7.5

CVE-2020-35610

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the corresponding terms.

28.12.2020
Высокая CVSS 7.5

CVE-2020-19455

РасширениеJdownloads Jdownloads
Разработчикcnvd.org.cn

SQL injection exists in the jdownloads 3.2.63 component for Joomla! via components/com_jdownloads/helpers/categories.php, order function via the filter_order parameter.

25.09.2020
Высокая CVSS 7.5

CVE-2020-19451

РасширениеJdownloads Jdownloads
Разработчикcnvd.org.cn

SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, updateLog function via the X-forwarded-for Header parameter.

25.09.2020
Высокая CVSS 7.5

CVE-2020-19450

РасширениеJdownloads Jdownloads
Разработчикcnvd.org.cn

SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, getUserLimits function in the list parameter.

25.09.2020
Высокая CVSS 7.5

CVE-2020-19447

РасширениеJdownloads Jdownloads
Разработчикcnvd.org.cn

SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_files_id parameter.

24.09.2020
Высокая CVSS 8.8

CVE-2020-25751

РасширениеCorephp Pago Commerce
Разработчикgeekwire.eu

The paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the administrator/index.php?option=com_pago&view=comments filter_published parameter.

18.09.2020
Высокая CVSS 7.5

CVE-2020-23971

РасширениеGmapfp Gmapfp
Разработчикpacketstormsecurity

gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload fil…

01.09.2020
Высокая CVSS 7.5

CVE-2020-23972

РасширениеGmapfp Gmapfp
Разработчикpacketstormsecurity

In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of u…

27.08.2020
Средняя CVSS 6.1

CVE-2020-24599

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.

26.08.2020
Средняя CVSS 6.1

CVE-2020-24598

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.

26.08.2020
Средняя CVSS 6.3

CVE-2020-15700

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.

15.07.2020
Средняя CVSS 5.3

CVE-2020-15699

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.

15.07.2020
Средняя CVSS 5.3

CVE-2020-15698

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials

15.07.2020
Средняя CVSS 4.3

CVE-2020-15697

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.

15.07.2020
Средняя CVSS 6.1

CVE-2020-15696

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.

15.07.2020
Средняя CVSS 6.3

CVE-2020-15695

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.

15.07.2020
Высокая CVSS 8.8

CVE-2020-13996

РасширениеJ2store J2store
Разработчикj2store

The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.

09.06.2020