Каталог CVE

Расширение: Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 1 461

Расширение: Joomla
Средняя CVSS 6.8

CVE-2007-1776

РасширениеDesign For Joomla D4j Ezine
Разработчикosvdb

SQL injection vulnerability in index.php in the DesignForJoomla.com D4J eZine (com_ezine) 2.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via…

30.03.2007
Высокая CVSS 10.0

CVE-2007-1699

РасширениеJoomla Swmenu Component
Разработчикosvdb

Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code…

27.03.2007
Высокая CVSS 7.5

CVE-2007-1703

РасширениеJoomla Rwcards Component
Разработчикosvdb

SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id p…

27.03.2007
Высокая CVSS 7.5

CVE-2007-1704

РасширениеJoomla Car Manager
Разработчикosvdb

SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

27.03.2007
Высокая CVSS 9.3

CVE-2007-1596

РасширениеJoomla Nfn Address Book
Разработчикosvdb

Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via…

22.03.2007
Средняя CVSS 6.8

CVE-2006-7122

РасширениеJoomla Bsq Sitestats
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in the IP Address Lookup functionality in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attack…

06.03.2007
Высокая CVSS 7.5

CVE-2006-7123

РасширениеJoomla Bsq Sitestats
Разработчикsecunia

Multiple SQL injection vulnerabilities in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allow remote attackers to execute arbitrary SQL commands via…

06.03.2007
Высокая CVSS 7.5

CVE-2006-7124

РасширениеJoomla Bsq Sitestats
Разработчикdeveloper.joomla

PHP remote file inclusion vulnerability in external/rssfeeds.php in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to execute…

06.03.2007
Средняя CVSS 6.8

CVE-2006-7125

РасширениеJoomla Bsq Sitestats
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header, which is not pro…

06.03.2007
Средняя CVSS 6.8

CVE-2006-7126

РасширениеJoomla Bsq Sitestats
Разработчикdeveloper.joomla

SQL injection vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the query string, possibly PHP_SELF.

06.03.2007
Высокая CVSS 7.5

CVE-2006-7008

РасширениеJoomla Joomla
Разработчикsecunia

Unspecified vulnerability in Joomla! before 1.0.10 has unknown impact and attack vectors, related to "securing mosmsg from misuse." NOTE: it is possible that this issue overlaps CVE-2006-10…

12.02.2007
Высокая CVSS 7.5

CVE-2006-7009

РасширениеJoomla Joomla
Разработчикsecunia

Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attack vectors.

12.02.2007
Высокая CVSS 7.5

CVE-2006-7010

РасширениеJoomla Joomla
Разработчикsecunia

The mosgetparam implementation in Joomla! before 1.0.10, does not set a variable's data type to integer when the variable's default value is numeric, which has unspecified impact and attack…

12.02.2007
Средняя CVSS 6.8

CVE-2006-6962

РасширениеJoomla Rs Gallery2
Разработчикsecurityfocus

PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to execute arbitrary PHP code via the mosCon…

29.01.2007
Средняя CVSS 6.8

CVE-2007-0373

РасширениеJoomla Joomla
Разработчикarchives.neohapsis

Multiple SQL injection vulnerabilities in Joomla! 1.5.0 Beta allow remote attackers to execute arbitrary SQL commands via (1) the searchword parameter in certain files; the where parameter…

19.01.2007
Высокая CVSS 7.5

CVE-2007-0374

РасширениеJoomla Joomla
Разработчикarchives.neohapsis

SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content e…

19.01.2007
Средняя CVSS 5.0

CVE-2007-0375

РасширениеJoomla Joomla
Разработчикarchives.neohapsis

Joomla! 1.5.0 Beta allows remote attackers to obtain sensitive information via a direct request for (1) plugins/user/example.php; (2) gmail.php, (3) example.php, or (4) ldap.php in plugins/…

19.01.2007
Высокая CVSS 7.5

CVE-2007-0382

РасширениеLetterman Letterman
Разработчикarchives.neohapsis

Multiple SQL injection vulnerabilities in letterman.class.php in the Letterman 1.2.3 (com_letterman) component for Joomla! before 1.0.12 allow remote attackers to execute arbitrary SQL comm…

19.01.2007