Каталог CVE

Расширение: Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 1 461

Расширение: Joomla
Средняя CVSS 5.0

CVE-2009-4232

РасширениеJonijnm Com Kide
Разработчикsecunia

The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an inser…

08.12.2009
Высокая CVSS 7.5

CVE-2009-4217

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

SQL injection vulnerability in the Itamar Elharar MusicGallery (com_musicgallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an…

07.12.2009
Высокая CVSS 7.5

CVE-2009-4202

РасширениеJoomla Joomla\!
Разработчикexploit-db

Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via di…

04.12.2009
Высокая CVSS 7.5

CVE-2009-4200

РасширениеVollmar Com Seminar
Разработчикexploit-db

SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action t…

04.12.2009
Средняя CVSS 6.8

CVE-2009-4199

РасширениеMamboforge Com Mosres
Разработчикexploit-db

Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to e…

04.12.2009
Средняя CVSS 4.3

CVE-2009-4168

РасширениеRoytanck Wp-cumulus
Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows re…

02.12.2009
Средняя CVSS 4.3

CVE-2009-4157

РасширениеJoomla Joomla\!
Разработчикwebsecurity.com.ua

Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject arbitrary we…

02.12.2009
Высокая CVSS 7.5

CVE-2009-4104

РасширениеJoomla Joomla\!
Разработчикosvdb

SQL injection vulnerability in Lyften Designs LyftenBloggie (com_lyftenbloggie) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the author paramete…

29.11.2009
Высокая CVSS 7.5

CVE-2009-4099

РасширениеG4j.laoneo Com Gcalendar
Разработчикosvdb

SQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary S…

29.11.2009
Высокая CVSS 7.5

CVE-2009-4094

РасширениеJoomla Joomla\!
Разработчикkamtiez

PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a…

29.11.2009
Средняя CVSS 6.8

CVE-2009-4059

РасширениеJoomla Joomla\!
Разработчикosvdb

SQL injection vulnerability in the JoomClip (com_joomclip) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a thumbs action to index.…

24.11.2009
Высокая CVSS 7.5

CVE-2009-4057

РасширениеJoomla Joomla\!
Разработчикosvdb

SQL injection vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in…

24.11.2009
Высокая CVSS 7.5

CVE-2009-3972

РасширениеJoomla Joomla\!
Разработчикexploit-db

SQL injection vulnerability in the Q-Proje Siirler Bileseni (com_siirler) component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an…

18.11.2009
Высокая CVSS 7.5

CVE-2009-3971

РасширениеJoomla Joomla\!
Разработчикexploit-db

SQL injection vulnerability in the jTips (com_jtips) component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder act…

18.11.2009
Высокая CVSS 7.5

CVE-2009-3964

РасширениеJoomla Joomla\!
Разработчикexploit-db

SQL injection vulnerability in the NinjaMonials (com_ninjacentral) component 1.1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a disp…

18.11.2009
Средняя CVSS 5.0

CVE-2009-3946

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.

16.11.2009
Средняя CVSS 5.5

CVE-2009-3945

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote authenticated users, with Author privileges, to replace the articles of…

16.11.2009
Высокая CVSS 7.5

CVE-2009-3835

РасширениеWhorl Ltd Jshop
Разработчикpacketstormsecurity

SQL injection vulnerability in the JShop (com_jshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.

02.11.2009