Каталог CVE

Расширение: Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 1 461

Расширение: Joomla
Высокая CVSS 7.5

CVE-2009-1258

РасширениеRd-media Com Rdautos
Разработчикosvdb

SQL injection vulnerability in the RD-Autos (com_rdautos) component 1.5.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the makeid parameter in index.php. NOTE:…

07.04.2009
Высокая CVSS 7.5

CVE-2008-6653

РасширениеJoomla Joomla
Разработчикforum.wh-com.de

SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL comma…

07.04.2009
Высокая CVSS 7.5

CVE-2008-6489

РасширениеJoomla Joomla
Разработчикsecurityfocus

SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the album parameter to index.php.

19.03.2009
Высокая CVSS 7.5

CVE-2008-6483

Разработчикosvdb

PHP remote file inclusion vulnerability in admin.googlebase.php in the Ecom Solutions VirtueMart Google Base (aka com_googlebase or Froogle) component 1.1 for Joomla! allows remote attacker…

18.03.2009
Средняя CVSS 6.8

CVE-2008-6482

РасширениеJustjoomla Com Treeg
Разработчикosvdb

PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Joomla!, when register_globals is enabled, allows remote attackers to exec…

18.03.2009
Высокая CVSS 7.5

CVE-2008-6481

РасширениеJoomla Joomla
Разработчикsecurityfocus

SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit…

17.03.2009
Высокая CVSS 7.5

CVE-2008-6430

РасширениеJoomla Com Mycontent
Разработчикosvdb

SQL injection vulnerability in the MyContent (com_mycontent) component 1.1.13 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to…

06.03.2009
Высокая CVSS 7.5

CVE-2008-6429

РасширениеJoomla Joomla
Разработчикosvdb

SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in…

06.03.2009
Высокая CVSS 7.5

CVE-2008-6347

РасширениеJoomla Joomla
Разработчикsecurityfocus

PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b component for Joomla! allows remote attackers to execute arbitrary PH…

02.03.2009
Высокая CVSS 7.5

CVE-2008-6337

РасширениеJoomlaapps Com Volunteer
Разработчикsecunia

SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the job_id parameter in a…

27.02.2009
Низкая CVSS 3.5

CVE-2008-6299

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the…

26.02.2009
Средняя CVSS 6.8

CVE-2009-0730

РасширениеGigcalendar Com Gigcalendar
Разработчикsecurityfocus

Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQ…

24.02.2009
Высокая CVSS 7.5

CVE-2009-0726

РасширениеGigcalendar Com Gigcalendar
Разработчикsecurityfocus

SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the gigcal_gigs_id parameter in…

24.02.2009
Высокая CVSS 7.5

CVE-2009-0706

Разработчикpacketstormsecurity

SQL injection vulnerability in the Simple Review (com_simple_review) component 1.3.5 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the category paramet…

23.02.2009
Высокая CVSS 7.5

CVE-2009-0702

РасширениеJoomla Joomla
Разработчикsecurityfocus

SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sec…

23.02.2009
Высокая CVSS 7.5

CVE-2008-6234

РасширениеJoomla Com Musica
Разработчикsecurityfocus

SQL injection vulnerability in the com_musica module in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

21.02.2009
Средняя CVSS 5.0

CVE-2008-6222

Разработчикsecunia

Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the i…

20.02.2009
Высокая CVSS 7.5

CVE-2008-6221

Разработчикsecunia

PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for Joomla! allows remote attackers to execute arbitrary PHP code via a…

20.02.2009