Каталог CVE

Расширение: Joomla Joomla\!

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 575

Расширение: Joomla Joomla\!
Средняя CVSS 4.3

CVE-2009-3368

РасширениеJoomlahbs Com Hbssearch
Разработчикe-rdc

Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allows remote attackers to inject arbitrary web script or H…

24.09.2009
Высокая CVSS 7.5

CVE-2009-3342

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) component 1.5.2 for Joomla! allows remote attackers to execute arbitrary S…

24.09.2009
Высокая CVSS 7.5

CVE-2009-3335

РасширениеJoomla Joomla\!
Разработчикexploit-db

SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.

24.09.2009
Высокая CVSS 7.5

CVE-2009-3334

РасширениеLhacky Com Jinc
Разработчикexploit-db

SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component (aka JINC or com_jinc) component 0.2 for Joomla! allows remote attackers to execute arbit…

23.09.2009
Высокая CVSS 7.5

CVE-2008-7169

РасширениеJabode Com Jabode
Разработчикsecurityfocus

SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.

08.09.2009
Высокая CVSS 7.5

CVE-2008-7033

РасширениеGalore Com Simpleshop
Разработчикosvdb

SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section…

24.08.2009
Высокая CVSS 7.5

CVE-2008-6881

РасширениеJoompolitan Com Livechat
Разработчикsecunia

Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to (1) getCh…

30.07.2009
Высокая CVSS 7.5

CVE-2009-2601

РасширениеJoomlaequipment Juser
Разработчикexploit-db

SQL injection vulnerability in the Joomlaequipment (aka JUser or com_juser) component 2.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a s…

27.07.2009
Высокая CVSS 7.5

CVE-2009-2567

РасширениеAlmondsoft Almond Classifieds
Разработчикexploit-db

SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 5.6.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

22.07.2009
Высокая CVSS 7.5

CVE-2009-2395

РасширениеJoomlaworks Com K2
Разработчикexploit-db

SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in an itemli…

09.07.2009
Высокая CVSS 7.5

CVE-2008-6852

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

07.07.2009
Высокая CVSS 7.5

CVE-2009-2290

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

SQL injection vulnerability in the Boy Scout Advancement (com_bsadv) component 0.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in…

01.07.2009
Высокая CVSS 7.5

CVE-2009-1822

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

Multiple PHP remote file inclusion vulnerabilities in the InterJoomla ArtForms (com_artforms) component 2.1b7 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in t…

29.05.2009
Высокая CVSS 7.5

CVE-2009-1736

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid paramete…

20.05.2009
Высокая CVSS 7.5

CVE-2009-1499

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in index.php. NOTE: Secur…

01.05.2009
Высокая CVSS 7.5

CVE-2008-6182

РасширениеJoomla Ignitegallery
Разработчикsecunia

SQL injection vulnerability in the Ignite Gallery (com_ignitegallery) component 0.8.0 through 0.8.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gallery par…

19.02.2009
Высокая CVSS 7.5

CVE-2008-4122

РасширениеJoomla Joomla\!
Разработчикint21.de

Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission wit…

19.12.2008
Средняя CVSS 5.0

CVE-2008-4764

РасширениеExtplorer Com Extplorer
Разработчикsecurityfocus

Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dir para…

28.10.2008