Каталог CVE

Расширение: Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 1 461

Расширение: Joomla
Высокая CVSS 8.8

CVE-2018-9107

РасширениеAcyba Acymailing
Разработчикvel.joomla

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CS…

28.03.2018
Высокая CVSS 8.8

CVE-2018-9106

РасширениеAcyba Acysms
Разработчикacyba

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in a CSV ex…

28.03.2018
Высокая CVSS 8.8

CVE-2018-8045

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.

15.03.2018
Средняя CVSS 6.1

CVE-2018-7717

Разработчикdebugtrap

The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated b…

05.03.2018
Высокая CVSS 7.5

CVE-2018-7482

РасширениеJoomlaworks K2
Разработчикexploit-db

The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=connector&cm…

28.02.2018
Критическая CVSS 9.8

CVE-2018-7318

РасширениеBelitsoft Checklist
Разработчикexploit-db

SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order parameter.

22.02.2018
Критическая CVSS 9.8

CVE-2018-7315

РасширениеHarmistechnology Ek Rishta
Разработчикexploit-db

SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter.

22.02.2018
Критическая CVSS 9.8

CVE-2018-7314

РасширениеMlwebtechnologies Prayercenter
Разработчикexploit-db

SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429.

22.02.2018
Критическая CVSS 9.8

CVE-2018-7313

РасширениеCwjoomla Cw Tags
Разработчикexploit-db

SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.

22.02.2018
Критическая CVSS 9.8

CVE-2018-7180

РасширениеSaxum2003 Astro
Разработчикexploit-db

SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter.

17.02.2018