Каталог CVE

Расширение: Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 1 461

Расширение: Joomla
Критическая CVSS 9.8

CVE-2015-4073

Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email para…

20.09.2017
Средняя CVSS 5.4

CVE-2015-4072

Разработчикpacketstormsecurity

Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to…

20.09.2017
Критическая CVSS 9.8

CVE-2013-7429

РасширениеMapsplugin Googlemaps
Разработчикseclists

The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php.

14.09.2017
Высокая CVSS 7.5

CVE-2017-2550

РасширениеKubik-rubik Easy Joomla Backup
Разработчикvapidlabs

Vulnerability in Easy Joomla Backup v3.2.4. The software creates a copy of the backup in the web root with an easily guessable filename.

08.09.2017
Высокая CVSS 7.5

CVE-2013-7428

РасширениеMapsplugin Googlemaps
Разработчикseclists

The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to cause a denial of service via the url parameter to plugin_googlemap2_proxy.php.

07.09.2017
Высокая CVSS 7.5

CVE-2013-7432

РасширениеMapsplugin Googlemaps
Разработчикsecurityvulns

The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism.

29.08.2017
Средняя CVSS 6.1

CVE-2013-7430

РасширениеMapsplugin Googlemaps
Разработчикmapsplugin

Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the xmlns parameter.

28.08.2017
Средняя CVSS 5.3

CVE-2015-4071

Разработчикpacketstormsecurity

The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/…

18.08.2017
Высокая CVSS 8.8

CVE-2017-11364

РасширениеJoomla Joomla\!
Разработчикjoomla

The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging C…

02.08.2017
Средняя CVSS 6.1

CVE-2017-11612

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.

26.07.2017
Критическая CVSS 9.8

CVE-2015-2798

РасширениеWeb-dorado Contact Form Maker
Разработчикsecurityfocus

SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

25.07.2017
Средняя CVSS 6.1

CVE-2017-9934

РасширениеJoomla Joomla\!
Разработчикjoomla

Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability.

17.07.2017
Высокая CVSS 7.5

CVE-2017-9933

РасширениеJoomla Joomla\!
Разработчикjoomla

Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents.

17.07.2017
Высокая CVSS 7.2

CVE-2016-10379

РасширениеVirtuemart Virtuemart
Разработчикcode610.blogspot

The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmethod_id pa…

29.05.2017
Критическая CVSS 9.8

CVE-2017-8917

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.

17.05.2017
Высокая CVSS 7.5

CVE-2017-9030

РасширениеCodextrous B2j Contact
Разработчикnavixia

The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a directory traversal attack that bypasses a uniqid protection mechanism, and makes it easier to read…

17.05.2017