Каталог CVE

Расширение: Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 1 461

Расширение: Joomla
Средняя CVSS 6.1

CVE-2015-7324

РасширениеStackideas Komento
Разработчикseclists

Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla! allow remote attackers to inject arbitr…

27.12.2017
Критическая CVSS 9.8

CVE-2017-17875

РасширениеJextn Jextn Faq Pro
Разработчикexploit-db

The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.

27.12.2017
Критическая CVSS 9.8

CVE-2017-17872

РасширениеJextn Jextn Video Gallery
Разработчикexploit-db

The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.

27.12.2017
Критическая CVSS 9.8

CVE-2017-17871

Разработчикexploit-db

The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.

27.12.2017
Критическая CVSS 9.8

CVE-2017-17870

РасширениеJbuildozer Jbuildozer
Разработчикvel.joomla

The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

27.12.2017
Критическая CVSS 9.8

CVE-2017-16634

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.

10.11.2017
Средняя CVSS 4.3

CVE-2017-16633

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.

10.11.2017
Критическая CVSS 9.8

CVE-2017-15965

РасширениеNswd Ns Download Shop
Разработчикsecurityfocus

The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.

29.10.2017
Критическая CVSS 9.8

CVE-2017-15946

РасширениеSelfget Tag Meta
Разработчикsecurityfocus

In the com_tag component 1.7.6 for Joomla!, a SQL injection vulnerability is located in the `tag` parameter to index.php. The request method to execute is GET.

28.10.2017
Высокая CVSS 8.8

CVE-2015-7715

Разработчикpacketstormsecurity

Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for r…

18.10.2017
Высокая CVSS 7.2

CVE-2015-7714

Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) cop…

18.10.2017
Средняя CVSS 5.9

CVE-2014-9686

РасширениеMapsplugin Googlemaps
Разработчикseclists

The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to p…

28.09.2017
Критическая CVSS 9.8

CVE-2017-14596

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

20.09.2017
Низкая CVSS 3.7

CVE-2017-14595

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.

20.09.2017
Средняя CVSS 6.1

CVE-2015-5608

РасширениеJoomla Joomla\!
Разработчикjoomla

Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.

20.09.2017
Высокая CVSS 7.5

CVE-2015-4074

Разработчикpacketstormsecurity

Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticke…

20.09.2017