Каталог CVE

Расширение: Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 1 461

Расширение: Joomla
Высокая CVSS 7.5

CVE-2008-3681

РасширениеJoomla Com User
Разработчикdeveloper.joomla

components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the "first enabled user (lowest id)" passwo…

14.08.2008
Высокая CVSS 7.5

CVE-2008-3586

РасширениеJoomla Com Ezstore
Разработчикsecurityfocus

SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.ph…

11.08.2008
Высокая CVSS 7.5

CVE-2008-3498

Разработчикsecunia

SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action…

06.08.2008
Средняя CVSS 6.8

CVE-2008-3265

РасширениеJoomla Com Dtregister
Разработчикosvdb

SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the eventId parameter in a pay_opti…

24.07.2008
Высокая CVSS 10.0

CVE-2008-3225

РасширениеJoomla Joomla
Разработчикjoomla

Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security fix."

18.07.2008
Средняя CVSS 5.0

CVE-2008-3226

РасширениеJoomla Joomla
Разработчикjoomla

The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.

18.07.2008
Высокая CVSS 7.5

CVE-2008-3227

РасширениеJoomla Joomla
Разработчикjoomla

Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redirect vulnerability.

18.07.2008
Высокая CVSS 7.5

CVE-2008-3228

РасширениеJoomla Joomla
Разработчикjoomla

Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.

18.07.2008
Высокая CVSS 7.5

CVE-2008-3132

РасширениеJoomla Com Beamospetition
Разработчикsecurityfocus

SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pet parameter to index.php.

10.07.2008
Высокая CVSS 7.5

CVE-2008-3083

Разработчикsecunia

SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

09.07.2008
Высокая CVSS 7.5

CVE-2008-2990

РасширениеJoomla Com Facileforms
Разработчикsecurityreason

PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP…

02.07.2008
Высокая CVSS 7.5

CVE-2008-2892

РасширениеFeellove Exp Shop Component
Разработчикsecunia

SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_payment actio…

27.06.2008
Высокая CVSS 7.5

CVE-2008-2692

РасширениеJoomla Com Yvcomment
Разработчикsecunia

SQL injection vulnerability in the yvComment (com_yvcomment) component 1.16.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the ArticleID parameter i…

13.06.2008
Высокая CVSS 7.5

CVE-2008-2697

РасширениеJoomla Com Rapidrecipe
Разработчикsecunia

SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter…

13.06.2008
Средняя CVSS 6.8

CVE-2008-2701

РасширениеJoomla Com Gameq
Разработчикpacketstormsecurity

SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a page…

13.06.2008
Высокая CVSS 7.5

CVE-2008-2676

РасширениеJoomla Com News Portal
Разработчикexchange.xforce.ibmcloud

SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid param…

12.06.2008
Высокая CVSS 7.5

CVE-2008-2643

РасширениеJoomla Com Biblestudy
Разработчикjoomlacode

SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a media…

10.06.2008
Высокая CVSS 7.5

CVE-2008-2651

РасширениеJoomla Com Joobb
Разработчикexchange.xforce.ibmcloud

SQL injection vulnerability in the Joomla! Bulletin Board (aka Joo!BB or com_joobb) component 0.5.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the forum param…

10.06.2008