Каталог CVE

Расширение: Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 1 461

Расширение: Joomla
Критическая CVSS 9.8

CVE-2018-6580

РасширениеJanguo Jimtawl
Разработчикexploit-db

Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request.

02.02.2018
Критическая CVSS 9.8

CVE-2018-6579

РасширениеJextn Reverse Auction
Разработчикexploit-db

SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.

02.02.2018
Критическая CVSS 9.8

CVE-2018-6578

РасширениеJextn Je Paypervideo
Разработчикexploit-db

SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.

02.02.2018
Критическая CVSS 9.8

CVE-2018-6577

РасширениеJextn Membership
Разработчикexploit-db

SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.

02.02.2018
Критическая CVSS 9.8

CVE-2018-6575

РасширениеJextn Classified
Разработчикexploit-db

SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request.

02.02.2018
Средняя CVSS 6.1

CVE-2018-6380

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.

30.01.2018
Средняя CVSS 6.1

CVE-2018-6379

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.

30.01.2018
Средняя CVSS 6.1

CVE-2018-6377

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox

30.01.2018
Критическая CVSS 9.8

CVE-2018-6376

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message.

30.01.2018
Критическая CVSS 9.8

CVE-2018-5985

РасширениеLivecrm Livecrm Saas Cloud
Разработчикexploit-db

SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request.

24.01.2018
Критическая CVSS 9.8

CVE-2018-5984

РасширениеTumder Project Tumder
Разработчикexploit-db

SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI.

24.01.2018
Критическая CVSS 9.8

CVE-2018-5696

РасширениеIjoomla Ad Agency
Разработчикvulnerability-lab

The iJoomla com_adagency plugin 6.0.9 for Joomla! allows SQL injection via the `advertiser_status` and `status_select` parameters to index.php.

14.01.2018